STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must be configured to restrict itself from accepting outbound packets that contain an illegitimate address in the source address field via an egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).

DISA Rule

SV-266259r1024876_rule

Vulnerability Number

V-266259

Group Title

SRG-NET-000364-FW-000042

Rule Version

F5BI-FW-300015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. VLANs.
3. VLAN List.
4. <Name> of internal VLAN.
5. Check the box next to "Source Check".
6. Set Auto Last Hop to "Disabled".

From the BIG-IP Console, type the following command(s):

tmsh modify net vlan <Name> auto-lasthop disabled
tmsh list net vlan <Name> source-checking enabled
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. Network.
2. VLANs.
3. VLAN List.
4. <Name> of internal VLAN.
5. Verify that "Source Check" is enabled.
6. Verify that Auto Last Hop is set to "Disabled".

From the BIG-IP Console, type the following command(s):

tmsh list net vlan <Name> auto-lasthop

tmsh list net vlan <Name> source-checking

If the BIG-IP appliance is not configured to disable Auto Last Hop, this is a finding.

Vulnerability Number

V-266259

Documentable

False

Rule Version

F5BI-FW-300015

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. VLANs.
3. VLAN List.
4. <Name> of internal VLAN.
5. Verify that "Source Check" is enabled.
6. Verify that Auto Last Hop is set to "Disabled".

From the BIG-IP Console, type the following command(s):

tmsh list net vlan <Name> auto-lasthop

tmsh list net vlan <Name> source-checking

If the BIG-IP appliance is not configured to disable Auto Last Hop, this is a finding.

Check Content Reference

M

Target Key

5641