SV-266262r1024580_rule
V-266262
SRG-NET-000392-FW-000042
F5BI-FW-300021
CAT III
10
From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. Check "Enabled" for "Dos Protection".
6. DoS Protection tab.
7. Set the "Publisher" for each DoS type to use a remote log destination (for production environments, use Remote High Speed Logging).
8. Click "Update".
From the BIG-IP Console, type the following commands:
tmsh modify security log profile global-network dos-network-publisher <publisher>
tmsh modify security log profile global-network protocol-dns-dos-publisher <publisher>
tmsh modify security log profile global-network protocol-sip-dos-publisher <publisher>
tmsh save sys config
From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. DoS Protection tab.
6. Verify the "Publisher" for each DoS type is configured to use a remote log destination (for production environments, use Remote High Speed Logging).
From the BIG-IP Console, type the following commands:
tmsh list security log profile global-network | grep dos
Verify each DoS publisher is configured to use a remote log destination.
If the BIG-IP is not configured to generate an alert when DoS incidents are detected, this is a finding.
V-266262
False
F5BI-FW-300021
From the BIG-IP GUI:
1. Security.
2. Event Logs.
3. Logging Profiles.
4. Edit the global-network profile.
5. DoS Protection tab.
6. Verify the "Publisher" for each DoS type is configured to use a remote log destination (for production environments, use Remote High Speed Logging).
From the BIG-IP Console, type the following commands:
tmsh list security log profile global-network | grep dos
Verify each DoS publisher is configured to use a remote log destination.
If the BIG-IP is not configured to generate an alert when DoS incidents are detected, this is a finding.
M
5641