SV-266256r1024869_rule
V-266256
F5BI-FW-300005
F5BI-FW-300005
CAT II
10
From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. Network Firewall tab.
6. Select a Log Publisher to use (for production environments, use Remote High Speed Logging).
7. Check the "Accept", "Drop", and "Reject" Log Rule Matches boxes are checked, along with any other settings to be enabled.
8. Click "Update".
From the BIG-IP Console, type the following commands:
tmsh modify security log profile global-network network modify { all { filter { log-acl-match-accept enabled log-acl-match-drop enabled log-acl-match-reject enabled } publisher <publisher name> } }
tmsh save sys config
Refer to vendor documentation for more information.
From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. Network Firewall tab.
6. Select a Log Publisher to use (for production environments, use Remote High Speed Logging).
7. Verify at least the "Accept", "Drop", and "Reject" Log Rule Matches boxes are checked, along with any other settings to be enabled.
From the BIG-IP Console, type the following commands:
tmsh list security log profile global-network
Note: Verify the log-acl-match-accept, log-acl-match-drop, and log-acl-match-reject settings are enabled.
If the BIG-IP is not configured to generate traffic log entries containing information to establish the details of the event, including success or failure of the application of the firewall rule, this is a finding.
V-266256
False
F5BI-FW-300005
From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. Network Firewall tab.
6. Select a Log Publisher to use (for production environments, use Remote High Speed Logging).
7. Verify at least the "Accept", "Drop", and "Reject" Log Rule Matches boxes are checked, along with any other settings to be enabled.
From the BIG-IP Console, type the following commands:
tmsh list security log profile global-network
Note: Verify the log-acl-match-accept, log-acl-match-drop, and log-acl-match-reject settings are enabled.
If the BIG-IP is not configured to generate traffic log entries containing information to establish the details of the event, including success or failure of the application of the firewall rule, this is a finding.
M
5641