STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

DISA Rule

SV-266261r1024579_rule

Vulnerability Number

V-266261

Group Title

SRG-NET-000202-FW-000039

Rule Version

F5BI-FW-300020

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Security.
2. Options.
3. Network Firewall.
4. Firewall Options.
5. Set "Virtual Server & Self IP Contexts" to "Drop" or "Reject".
6. Set "Global Context" to "Drop" or "Reject".
7. Update.

Check Contents

From the BIG-IP GUI:
1. Security.
2. Options.
3. Network Firewall.
4. Firewall Options.
5. Verify "Virtual Server & Self IP Contexts" is set to "Drop" or "Reject".
6. Verify "Global Context" is set to "Drop" or "Reject".

If the BIG-IP appliance is not configured to deny network communications traffic by default and allow network communications traffic by exception, this is a finding.

Vulnerability Number

V-266261

Documentable

False

Rule Version

F5BI-FW-300020

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. Options.
3. Network Firewall.
4. Firewall Options.
5. Verify "Virtual Server & Self IP Contexts" is set to "Drop" or "Reject".
6. Verify "Global Context" is set to "Drop" or "Reject".

If the BIG-IP appliance is not configured to deny network communications traffic by default and allow network communications traffic by exception, this is a finding.

Check Content Reference

M

Target Key

5641