STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must not use the On-demand Cert Auth VPE agent as part of the APM Policy Profiles.

DISA Rule

SV-266166r1111861_rule

Vulnerability Number

V-266166

Group Title

SRG-NET-000230-ALG-000113

Rule Version

F5BI-AP-300155

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Remove any "On-Demand Cert Auth" agents in the profile.
6. Add a "Client Cert Inspection" object in place of the previous "On Demand Cert Auth" agent.
7. Click "Apply Access Policy".

Note: Since use of this setting represent a risk to the DOD requirement for mutual authentication (see vulnerability discussion), if applications that use this function are mission essential, then AO approval is required, and use must be documented.

Check Contents

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify the On-Demand Cert Auth agent is not configured in any part of the profile.

If the On-Demand Cert Auth agent is used in any Access Policy Profile, this is a finding.

Vulnerability Number

V-266166

Documentable

False

Rule Version

F5BI-AP-300155

Severity Override Guidance

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Verify the On-Demand Cert Auth agent is not configured in any part of the profile.

If the On-Demand Cert Auth agent is used in any Access Policy Profile, this is a finding.

Check Content Reference

M

Target Key

5640