STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, the F5 BIG-IP appliance must be configured to enable the HTTP Only flag.

DISA Rule

SV-266162r1024392_rule

Vulnerability Number

V-266162

Group Title

SRG-NET-000233-ALG-000115

Rule Version

F5BI-AP-300151

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, set the HTTP Only flag.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains.
6. Under Cookie Options, Check the box next to HTTP Only.
7. Click "Update".
8. Click "Apply Access Policy".

Check Contents

If the Access Profile Type is not LTM+APM and it uses connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, then this is not a finding.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains.
6. Under Cookie Options, verify HTTP Only is enabled.

If the F5 BIG-IP appliance does not enable the HTTP Only flag, this is a finding.

Vulnerability Number

V-266162

Documentable

False

Rule Version

F5BI-AP-300151

Severity Override Guidance

If the Access Profile Type is not LTM+APM and it uses connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, then this is not a finding.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains.
6. Under Cookie Options, verify HTTP Only is enabled.

If the F5 BIG-IP appliance does not enable the HTTP Only flag, this is a finding.

Check Content Reference

M

Target Key

5640