SV-266260r1024878_rule
V-266260
SRG-NET-000362-FW-000028
F5BI-FW-300017
CAT I
10
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand each of the applicable families (Network, DNS, SIP) one at a time depending on the traffic being handled by the BIG-IP and do the following for each.
- Check the box at the top of the list of signatures to select all or, at a minimum, filters that prevent or limit the effects of all types of commonly known DoS attacks, including flooding, packet sweeps, unauthorized port scanning and unknown or out-of-order extension headers.
- Set "Set State" to "Mitigate".
5. Click "Commit Changes to System".
At a minimum, select filters that prevent or limit the effects of all types of commonly known DoS attacks, including flooding, packet sweeps, unauthorized port scanning. Also, select filters for unknown or out-of-order extension headers.
Note: Sites must operationally test or initially use learning mode prior to turning on all of the options in all families to prevent operational impacts, particularly in implementations with large traffic volumes.
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand each of the applicable families (Network, DNS, SIP) depending on the traffic being handled by the BIG-IP and verify the "State" is set to "Mitigate" for all signatures in that family.
If the BIG-IP appliance is not configured to block outbound traffic containing denial-of-service DoS attacks, this is a finding.
V-266260
False
F5BI-FW-300017
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand each of the applicable families (Network, DNS, SIP) depending on the traffic being handled by the BIG-IP and verify the "State" is set to "Mitigate" for all signatures in that family.
If the BIG-IP appliance is not configured to block outbound traffic containing denial-of-service DoS attacks, this is a finding.
M
5641