STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN must use AES256 or greater encryption for the IPsec proposal.

DISA Rule

SV-266279r1024915_rule

Vulnerability Number

V-266279

Group Title

SRG-NET-000525-VPN-002330

Rule Version

F5BI-VN-300006

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Configure AES256 or greater encryption algorithm.
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the Name of the IPsec Policy.
5. Verify an AES256 or greater encryption algorithm is selected.

If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IPsec proposal, this is a finding.

Vulnerability Number

V-266279

Documentable

False

Rule Version

F5BI-VN-300006

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the Name of the IPsec Policy.
5. Verify an AES256 or greater encryption algorithm is selected.

If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IPsec proposal, this is a finding.

Check Content Reference

M

Target Key

5642