STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must be configured to use filters that use packet headers and packet attributes, including source and destination IP addresses and ports, to prevent the flow of unauthorized or suspicious traffic between interconnected networks with different security policies, including perimeter firewalls and server VLANs.

DISA Rule

SV-266255r1024867_rule

Vulnerability Number

V-266255

Group Title

SRG-NET-000019-FW-000003

Rule Version

F5BI-FW-300002

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
5. Configure rules to use packet headers and packet attributes, including source and destination IP addresses and ports in accordance with the SSP and site configuration documentation.

Check Contents

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules in the policy do not use packet headers and packet attributes, including source and destination IP addresses and ports, this is a finding.

Vulnerability Number

V-266255

Documentable

False

Rule Version

F5BI-FW-300002

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules in the policy do not use packet headers and packet attributes, including source and destination IP addresses and ports, this is a finding.

Check Content Reference

M

Target Key

5641