STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must be configured to filter inbound traffic on all external interfaces.

DISA Rule

SV-266264r1024582_rule

Vulnerability Number

V-266264

Group Title

SRG-NET-000364-FW-000031

Rule Version

F5BI-FW-300029

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
5. Configure rules to using packet headers and packet attributes, including source and destination IP addresses and ports to filter inbound traffic on all external interfaces.

Check Contents

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules in the policy do not filter inbound traffic on all active external interfaces, this is a finding.

Vulnerability Number

V-266264

Documentable

False

Rule Version

F5BI-FW-300029

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules in the policy do not filter inbound traffic on all active external interfaces, this is a finding.

Check Content Reference

M

Target Key

5641