STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must be configured to use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network.

DISA Rule

SV-266170r1137561_rule

Vulnerability Number

V-266170

Group Title

SRG-NET-000510-ALG-000111

Rule Version

F5BI-AP-300159

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. SSL.
4. Client.
5. Click the name of the SSL Profile.
6. For "Ciphers", configure only AES-256 or other cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network in compliance with CSNA/CNSSP-15.
7. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. SSL.
4. Client.
5. Click the name of the SSL Profile.
6. For "Ciphers", ensure only AES-256 or other cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network are configured in compliance with CSNA/CNSSP-15.

If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network, this is a finding.

Vulnerability Number

V-266170

Documentable

False

Rule Version

F5BI-AP-300159

Severity Override Guidance

From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. SSL.
4. Client.
5. Click the name of the SSL Profile.
6. For "Ciphers", ensure only AES-256 or other cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network are configured in compliance with CSNA/CNSSP-15.

If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network, this is a finding.

Check Content Reference

M

Target Key

5640