STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN Gateway must renegotiate the IPsec Phase 1 security association after eight hours or less.

DISA Rule

SV-266283r1024758_rule

Vulnerability Number

V-266283

Group Title

SRG-NET-000337-VPN-001290

Rule Version

F5BI-VN-300025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Configure the value for "Lifetime" under "IKE Phase 1 Algorithms" to 480 minutes or less, or an organization-defined time period.
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify that the value for "Lifetime" under "IKE Phase 1 Algorithms" is set to 480 minutes or less, or an organization-defined time period.

If the BIG-IP appliance is not configured to renegotiate the security association after 8 hours or less, or an organization-defined period, this is a finding.

Vulnerability Number

V-266283

Documentable

False

Rule Version

F5BI-VN-300025

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify that the value for "Lifetime" under "IKE Phase 1 Algorithms" is set to 480 minutes or less, or an organization-defined time period.

If the BIG-IP appliance is not configured to renegotiate the security association after 8 hours or less, or an organization-defined period, this is a finding.

Check Content Reference

M

Target Key

5642