STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must generate an alert that can be forwarded to, at a minimum, the information system security officer (ISSO) and information system security manager (ISSM) when denial-of-service (DoS) incidents are detected.

DISA Rule

SV-266262r1024580_rule

Vulnerability Number

V-266262

Group Title

SRG-NET-000392-FW-000042

Rule Version

F5BI-FW-300021

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. Check "Enabled" for "Dos Protection".
6. DoS Protection tab.
7. Set the "Publisher" for each DoS type to use a remote log destination (for production environments, use Remote High Speed Logging).
8. Click "Update".

From the BIG-IP Console, type the following commands:

tmsh modify security log profile global-network dos-network-publisher <publisher>
tmsh modify security log profile global-network protocol-dns-dos-publisher <publisher>
tmsh modify security log profile global-network protocol-sip-dos-publisher <publisher>
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. DoS Protection tab.
6. Verify the "Publisher" for each DoS type is configured to use a remote log destination (for production environments, use Remote High Speed Logging).

From the BIG-IP Console, type the following commands:

tmsh list security log profile global-network | grep dos

Verify each DoS publisher is configured to use a remote log destination.

If the BIG-IP is not configured to generate an alert when DoS incidents are detected, this is a finding.

Vulnerability Number

V-266262

Documentable

False

Rule Version

F5BI-FW-300021

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. DoS Protection tab.
6. Verify the "Publisher" for each DoS type is configured to use a remote log destination (for production environments, use Remote High Speed Logging).

From the BIG-IP Console, type the following commands:

tmsh list security log profile global-network | grep dos

Verify each DoS publisher is configured to use a remote log destination.

If the BIG-IP is not configured to generate an alert when DoS incidents are detected, this is a finding.

Check Content Reference

M

Target Key

5641