STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance that filters traffic from the VPN access points must be configured with organization-defined filtering rules that apply to the monitoring of remote access traffic.

DISA Rule

SV-266254r1024572_rule

Vulnerability Number

V-266254

Group Title

SRG-NET-000061-FW-000001

Rule Version

F5BI-FW-300001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the VPN is terminated directly on the BIG-IP, an Access Control List can be used to filter remote VPN traffic.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" on the VPN profile.
5. Add an "Advanced Resource Assign" object in the Visual Policy Editor and add an Access Control List in accordance with the SSP and site configuration documentation.

If the VPN is not terminated directly on the BIG-IP and the BIG-IP filters traffic from the VPN access points:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
5. Add rules to filter VPN traffic.
6. Click "Commit Changes to System".

Check Contents

If the VPN is terminated directly on the BIG-IP, an Access Control List can be used to filter remote VPN traffic.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" on the VPN profile.
5. Access Control Lists are assigned in an "Advanced Resource Assign" object in the Visual Policy Editor.

If the VPN is terminated directly on the BIG-IP appliance configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, and there is no Access Control List assigned in the Access Profile, this is a finding.

If the VPN is not terminated directly on the BIG-IP and the BIG-IP filters traffic from the VPN access points:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If the BIG-IP appliance filters traffic from the VPN access points and there are no rules configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, this is a finding.

Vulnerability Number

V-266254

Documentable

False

Rule Version

F5BI-FW-300001

Severity Override Guidance

If the VPN is terminated directly on the BIG-IP, an Access Control List can be used to filter remote VPN traffic.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" on the VPN profile.
5. Access Control Lists are assigned in an "Advanced Resource Assign" object in the Visual Policy Editor.

If the VPN is terminated directly on the BIG-IP appliance configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, and there is no Access Control List assigned in the Access Profile, this is a finding.

If the VPN is not terminated directly on the BIG-IP and the BIG-IP filters traffic from the VPN access points:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If the BIG-IP appliance filters traffic from the VPN access points and there are no rules configured with organization-defined filtering rules that apply to the monitoring of remote access traffic, this is a finding.

Check Content Reference

M

Target Key

5641