STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN Gateway must use Internet Key Exchange (IKE) for IPsec VPN Security Associations (SAs).

DISA Rule

SV-266281r1024756_rule

Vulnerability Number

V-266281

Group Title

SRG-NET-000512-VPN-002220

Rule Version

F5BI-VN-300021

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. Manual Security Associations.
4. Delete any entries in this list.

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. Manual Security Associations.
4. Verify there are no Manual Security Associations listed.

If the BIG-IP appliance is not configured to use IKE for IPsec VPN SAs, this is a finding.

Vulnerability Number

V-266281

Documentable

False

Rule Version

F5BI-VN-300021

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. Manual Security Associations.
4. Verify there are no Manual Security Associations listed.

If the BIG-IP appliance is not configured to use IKE for IPsec VPN SAs, this is a finding.

Check Content Reference

M

Target Key

5642