STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP appliance IPsec VPN Gateway must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation.

DISA Rule

SV-266288r1024921_rule

Vulnerability Number

V-266288

Group Title

SRG-NET-000371-VPN-001640

Rule Version

F5BI-VN-300044

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Network
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Select any value other than "NONE" in "IKE Phase 2 >> Perfect Forward Secrecy".
6. Click "Update".

Check Contents

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify "NONE" is not selected in "IKE Phase 2 >> Perfect Forward Secrecy".

If the BIG-IP appliance is not configured to specify PFS during IKE negotiation, this is a finding.

Vulnerability Number

V-266288

Documentable

False

Rule Version

F5BI-VN-300044

Severity Override Guidance

From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify "NONE" is not selected in "IKE Phase 2 >> Perfect Forward Secrecy".

If the BIG-IP appliance is not configured to specify PFS during IKE negotiation, this is a finding.

Check Content Reference

M

Target Key

5642