STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN must ensure inbound and outbound traffic is configured with a security policy.

DISA Rule

SV-266280r1024917_rule

Vulnerability Number

V-266280

Group Title

SRG-NET-000019-VPN-000040

Rule Version

F5BI-VN-300009

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on IPsec Policy for site to site IPsec.
5. Select "ESP" in the IPsec Protocol section.
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on IPsec Policy for site to site IPsec.
5. Verify that "ESP" is selected in the IPsec Protocol section.

If the BIG-IP is not configured to ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies, this is a finding.

Vulnerability Number

V-266280

Documentable

False

Rule Version

F5BI-VN-300009

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on IPsec Policy for site to site IPsec.
5. Verify that "ESP" is selected in the IPsec Protocol section.

If the BIG-IP is not configured to ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies, this is a finding.

Check Content Reference

M

Target Key

5642