STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must be configured to limit authenticated client sessions to initial session source IP.

DISA Rule

SV-266168r1024400_rule

Vulnerability Number

V-266168

Group Title

SRG-NET-000230-ALG-000113

Rule Version

F5BI-AP-300157

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Note: Setting must be tested. If there are operational impacts that prevent the use of this setting, document the impacts, and obtain approval from the AO if this requirement will not be implemented.

From the BIG-IP GUI:
1. System.
2. Access.
3. Profiles/Policies.
4. Access Profiles.
5. Click the access profile name.
6. Under Settings, check "Restrict to Single Client IP".
Note: If the box is grayed out, check the box all the way to the right of the setting first and then check the box.
7. Click "Update".
8. Click "Apply Access Policy".

Check Contents

If the site has documented an adverse operational impact and has AO approval, this is not a finding.

From the BIG-IP GUI:
1. System.
2. Access.
3. Profiles/Policies.
4. Access Profiles.
5. Click the access profile name.
6. Under Settings, verify "Restrict to Single Client IP" is checked.

If the BIG-IP appliance is not configured to limit authenticated client sessions to initial session source IP, this is a finding.

Vulnerability Number

V-266168

Documentable

False

Rule Version

F5BI-AP-300157

Severity Override Guidance

If the site has documented an adverse operational impact and has AO approval, this is not a finding.

From the BIG-IP GUI:
1. System.
2. Access.
3. Profiles/Policies.
4. Access Profiles.
5. Click the access profile name.
6. Under Settings, verify "Restrict to Single Client IP" is checked.

If the BIG-IP appliance is not configured to limit authenticated client sessions to initial session source IP, this is a finding.

Check Content Reference

M

Target Key

5640