STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS Firewall Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The BIG-IP appliance perimeter firewall must be configured to filter traffic destined to the enclave in accordance with the specific traffic that is approved and registered in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments.

DISA Rule

SV-266267r1024585_rule

Vulnerability Number

V-266267

Group Title

SRG-NET-000205-FW-000040

Rule Version

F5BI-FW-300033

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
5. Configure rules to use packet headers and packet attributes, including source and destination IP addresses and ports to only allow inbound traffic in accordance with the PPSM CAL.

Check Contents

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules are not configured to only allow inbound traffic in accordance with the PPSM CAL, this is a finding.

Vulnerability Number

V-266267

Documentable

False

Rule Version

F5BI-FW-300033

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules are not configured to only allow inbound traffic in accordance with the PPSM CAL, this is a finding.

Check Content Reference

M

Target Key

5641