STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning.

DISA Rule

SV-266260r1024878_rule

Vulnerability Number

V-266260

Group Title

SRG-NET-000362-FW-000028

Rule Version

F5BI-FW-300017

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand each of the applicable families (Network, DNS, SIP) one at a time depending on the traffic being handled by the BIG-IP and do the following for each.
- Check the box at the top of the list of signatures to select all or, at a minimum, filters that prevent or limit the effects of all types of commonly known DoS attacks, including flooding, packet sweeps, unauthorized port scanning and unknown or out-of-order extension headers.
- Set "Set State" to "Mitigate".
5. Click "Commit Changes to System".

At a minimum, select filters that prevent or limit the effects of all types of commonly known DoS attacks, including flooding, packet sweeps, unauthorized port scanning. Also, select filters for unknown or out-of-order extension headers.

Note: Sites must operationally test or initially use learning mode prior to turning on all of the options in all families to prevent operational impacts, particularly in implementations with large traffic volumes.

Check Contents

From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand each of the applicable families (Network, DNS, SIP) depending on the traffic being handled by the BIG-IP and verify the "State" is set to "Mitigate" for all signatures in that family.

If the BIG-IP appliance is not configured to block outbound traffic containing denial-of-service DoS attacks, this is a finding.

Vulnerability Number

V-266260

Documentable

False

Rule Version

F5BI-FW-300017

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand each of the applicable families (Network, DNS, SIP) depending on the traffic being handled by the BIG-IP and verify the "State" is set to "Mitigate" for all signatures in that family.

If the BIG-IP appliance is not configured to block outbound traffic containing denial-of-service DoS attacks, this is a finding.

Check Content Reference

M

Target Key

5641