STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN Gateway must use AES256 or higher encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions.

DISA Rule

SV-266278r1024913_rule

Vulnerability Number

V-266278

Group Title

SRG-NET-000317-VPN-001090

Rule Version

F5BI-VN-300005

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Configure an AES256 encryption algorithm under IKE Phase 1 Algorithms >> Encryption Algorithm.
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify an AES256 encryption algorithm is selected under IKE Phase 1 Algorithms >> Encryption Algorithm.

If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IKE proposal, this is a finding.

Vulnerability Number

V-266278

Documentable

False

Rule Version

F5BI-VN-300005

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify an AES256 encryption algorithm is selected under IKE Phase 1 Algorithms >> Encryption Algorithm.

If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IKE proposal, this is a finding.

Check Content Reference

M

Target Key

5642