STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must be configured to use TCP when sending log records to the central audit server.

DISA Rule

SV-266258r1024873_rule

Vulnerability Number

V-266258

Group Title

SRG-NET-000098-FW-000021

Rule Version

F5BI-FW-300013

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Log Destinations.
5. Click the name of the log destination.
6. Set "Protocol" to TCP.
7. Click "Update".

From the BIG-IP Console, type the following commands:

tmsh modify sys log-config destination remote-high-speed-log <Name> protocol tcp

Check Contents

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Log Destinations.
5. <Name>.
6. Verify "Protocol" is set to TCP.

From the BIG-IP Console, type the following command(s):

tmsh list sys log-config destination remote-high-speed-log <Name> protocol

Note: Verify this is set to "tcp".

If the BIG-IP appliance is not configured to use TCP when sending log records to the central audit server, this is a finding.

Vulnerability Number

V-266258

Documentable

False

Rule Version

F5BI-FW-300013

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Log Destinations.
5. <Name>.
6. Verify "Protocol" is set to TCP.

From the BIG-IP Console, type the following command(s):

tmsh list sys log-config destination remote-high-speed-log <Name> protocol

Note: Verify this is set to "tcp".

If the BIG-IP appliance is not configured to use TCP when sending log records to the central audit server, this is a finding.

Check Content Reference

M

Target Key

5641