STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing remote access intermediary services must be configured to route sessions to an IDPS for inspection.

DISA Rule

SV-266173r1024854_rule

Vulnerability Number

V-266173

Group Title

SRG-NET-000512-ALG-000062

Rule Version

F5BI-AP-300162

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure one of these two options:
1. Configure the network architecture to route traffic inline from the BIG-IP through an IDPS.
2. Configure a Protocol Inspection Profile on the Virtual Server.

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click on the name of the Virtual Server.
5. Security >> Policies tab.
6. Set "Protocol Inspection Profile" to "Enabled".
7. Set the "Profile" drop-down to the appropriate value.
Note: To create a Protocol Inspection Profile, go to Security >> Protocol Security >> Inspection Profiles.
8. Click "Update".

Check Contents

If the BIG-IP appliance does not provide remote access intermediary services, this is not applicable.

Verify one of these two options are configured:
1. The network architecture routes traffic inline from the BIG-IP through an IDPS.
2. A Protocol Inspection Profile is configured on the Virtual Server.

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click on the name of the Virtual Server.
5. Security >> Policies tab.
6. Verify "Protocol Inspection Profile" is set to "Enabled" and the "Profile" drop-down is set to the appropriate value.

If the BIG-IP appliance is not configured to route sessions to an IDPS for inspection, this is a finding.

Vulnerability Number

V-266173

Documentable

False

Rule Version

F5BI-AP-300162

Severity Override Guidance

If the BIG-IP appliance does not provide remote access intermediary services, this is not applicable.

Verify one of these two options are configured:
1. The network architecture routes traffic inline from the BIG-IP through an IDPS.
2. A Protocol Inspection Profile is configured on the Virtual Server.

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click on the name of the Virtual Server.
5. Security >> Policies tab.
6. Verify "Protocol Inspection Profile" is set to "Enabled" and the "Profile" drop-down is set to the appropriate value.

If the BIG-IP appliance is not configured to route sessions to an IDPS for inspection, this is a finding.

Check Content Reference

M

Target Key

5640