SV-266258r1024873_rule
V-266258
SRG-NET-000098-FW-000021
F5BI-FW-300013
CAT II
10
From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Log Destinations.
5. Click the name of the log destination.
6. Set "Protocol" to TCP.
7. Click "Update".
From the BIG-IP Console, type the following commands:
tmsh modify sys log-config destination remote-high-speed-log <Name> protocol tcp
From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Log Destinations.
5. <Name>.
6. Verify "Protocol" is set to TCP.
From the BIG-IP Console, type the following command(s):
tmsh list sys log-config destination remote-high-speed-log <Name> protocol
Note: Verify this is set to "tcp".
If the BIG-IP appliance is not configured to use TCP when sending log records to the central audit server, this is a finding.
V-266258
False
F5BI-FW-300013
From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Log Destinations.
5. <Name>.
6. Verify "Protocol" is set to TCP.
From the BIG-IP Console, type the following command(s):
tmsh list sys log-config destination remote-high-speed-log <Name> protocol
Note: Verify this is set to "tcp".
If the BIG-IP appliance is not configured to use TCP when sending log records to the central audit server, this is a finding.
M
5641