STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN must use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.

DISA Rule

SV-266286r1024761_rule

Vulnerability Number

V-266286

Group Title

SRG-NET-000565-VPN-002400

Rule Version

F5BI-VN-300040

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Configure "IKE Phase 1 Algorithms" to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
6. Click "Update".

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Configure "IKE Phase 2" to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify that "IKE Phase 1 Algorithms" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify that "IKE Phase 2" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.

If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network, this is a finding.

Vulnerability Number

V-266286

Documentable

False

Rule Version

F5BI-VN-300040

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify that "IKE Phase 1 Algorithms" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify that "IKE Phase 2" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.

If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network, this is a finding.

Check Content Reference

M

Target Key

5642