SV-266254r1024572_rule
V-266254
SRG-NET-000061-FW-000001
F5BI-FW-300001
CAT II
10
If the VPN is terminated directly on the BIG-IP, an Access Control List can be used to filter remote VPN traffic.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" on the VPN profile.
5. Add an "Advanced Resource Assign" object in the Visual Policy Editor and add an Access Control List in accordance with the SSP and site configuration documentation.
If the VPN is not terminated directly on the BIG-IP and the BIG-IP filters traffic from the VPN access points:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
5. Add rules to filter VPN traffic.
6. Click "Commit Changes to System".
If the VPN is terminated directly on the BIG-IP, an Access Control List can be used to filter remote VPN traffic.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" on the VPN profile.
5. Access Control Lists are assigned in an "Advanced Resource Assign" object in the Visual Policy Editor.
If the VPN is terminated directly on the BIG-IP appliance configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, and there is no Access Control List assigned in the Access Profile, this is a finding.
If the VPN is not terminated directly on the BIG-IP and the BIG-IP filters traffic from the VPN access points:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
If the BIG-IP appliance filters traffic from the VPN access points and there are no rules configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, this is a finding.
V-266254
False
F5BI-FW-300001
If the VPN is terminated directly on the BIG-IP, an Access Control List can be used to filter remote VPN traffic.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" on the VPN profile.
5. Access Control Lists are assigned in an "Advanced Resource Assign" object in the Visual Policy Editor.
If the VPN is terminated directly on the BIG-IP appliance configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, and there is no Access Control List assigned in the Access Profile, this is a finding.
If the VPN is not terminated directly on the BIG-IP and the BIG-IP filters traffic from the VPN access points:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
If the BIG-IP appliance filters traffic from the VPN access points and there are no rules configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, this is a finding.
M
5641