STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1.

DISA Rule

SV-266277r1024911_rule

Vulnerability Number

V-266277

Group Title

SRG-NET-000074-VPN-000250

Rule Version

F5BI-VN-300004

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the IKE Peer Name.
5. In "IKE Phase 1 Algorithms", select "MODP4096" or higher for "Perfect Forward Secrecy".
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the IKE Peer Name.
5. In "IKE Phase 1 Algorithms", verify "MODP4096" or higher is selected for "Perfect Forward Secrecy".

If the BIG-IP appliance is not configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1, this is a finding.

Vulnerability Number

V-266277

Documentable

False

Rule Version

F5BI-VN-300004

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the IKE Peer Name.
5. In "IKE Phase 1 Algorithms", verify "MODP4096" or higher is selected for "Perfect Forward Secrecy".

If the BIG-IP appliance is not configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1, this is a finding.

Check Content Reference

M

Target Key

5642