STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN must be configured to use FIPS-validated SHA-2 or higher for Internet Key Exchange (IKE).

DISA Rule

SV-266287r1024762_rule

Vulnerability Number

V-266287

Group Title

SRG-NET-000230-VPN-000780

Rule Version

F5BI-VN-300041

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Configure SHA-2 or higher for the following:
IKE Phase 1 Algorithms >> Authentication Algorithm
IKE Phase 1 Algorithms >> Pseudo-Random Function
6. Click "Update".

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click the name of the IPsec Policy.
5. Configure SHA-2 or higher for the following:
IKE Phase 2 >> Authentication Algorithm
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify "SHA-1" or "MD5" is not selected for the following:
IKE Phase 1 Algorithms >> Authentication Algorithm
IKE Phase 1 Algorithms >> Pseudo-Random Function

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click the name of the IPsec Policy.
5. Verify "SHA-1" is not selected for the following:
IKE Phase 2 >> Authentication Algorithm

If the BIG-IP appliance is not configured to use FIPS-validated SHA-2 or higher for IKE, this is a finding.

Vulnerability Number

V-266287

Documentable

False

Rule Version

F5BI-VN-300041

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify "SHA-1" or "MD5" is not selected for the following:
IKE Phase 1 Algorithms >> Authentication Algorithm
IKE Phase 1 Algorithms >> Pseudo-Random Function

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click the name of the IPsec Policy.
5. Verify "SHA-1" is not selected for the following:
IKE Phase 2 >> Authentication Algorithm

If the BIG-IP appliance is not configured to use FIPS-validated SHA-2 or higher for IKE, this is a finding.

Check Content Reference

M

Target Key

5642