STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must be configured to disable the persistent cookie flag.

DISA Rule

SV-266164r1024395_rule

Vulnerability Number

V-266164

Group Title

SRG-NET-000233-ALG-000115

Rule Version

F5BI-AP-300153

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Note: Testing must be performed prior to implementation to prevent operational impact. This setting may break access to certain applications that require cookie persistence.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains tab.
6. Under Cookie Options, uncheck "Persistent".
7. Click "Update".
8. Click "Apply Access Policy".

Check Contents

If the Access Profile is used for applications that require cookie persistence, then this is not a finding.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains tab.
6. Under Cookie Options, verify "Persistent" is disabled.

If the F5 Big IP appliance APM Policy has the Persistent cookies flag enabled, this is a finding.

Vulnerability Number

V-266164

Documentable

False

Rule Version

F5BI-AP-300153

Severity Override Guidance

If the Access Profile is used for applications that require cookie persistence, then this is not a finding.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains tab.
6. Under Cookie Options, verify "Persistent" is disabled.

If the F5 Big IP appliance APM Policy has the Persistent cookies flag enabled, this is a finding.

Check Content Reference

M

Target Key

5640