STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The IPsec BIG-IP appliance must use IKEv2 for IPsec VPN security associations.

DISA Rule

SV-266282r1024757_rule

Vulnerability Number

V-266282

Group Title

SRG-NET-000132-VPN-000460

Rule Version

F5BI-VN-300024

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Select "Version 2" for "Version".
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify "Version 2" is selected for "Version".

If the BIG-IP appliance is not configured to use IKEv2 for IPsec VPN security associations, this is a finding.

Vulnerability Number

V-266282

Documentable

False

Rule Version

F5BI-VN-300024

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify "Version 2" is selected for "Version".

If the BIG-IP appliance is not configured to use IKEv2 for IPsec VPN security associations, this is a finding.

Check Content Reference

M

Target Key

5642