STIGQter STIGQter: STIG Summary:

F5 BIG-IP TMOS VPN Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 Sep 2024

CheckedNameTitle
SV-266277r1024911_ruleThe F5 BIG-IP appliance must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1.
SV-266278r1024913_ruleThe F5 BIG-IP appliance IPsec VPN Gateway must use AES256 or higher encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions.
SV-266279r1024915_ruleThe F5 BIG-IP appliance IPsec VPN must use AES256 or greater encryption for the IPsec proposal.
SV-266280r1024917_ruleThe F5 BIG-IP appliance IPsec VPN must ensure inbound and outbound traffic is configured with a security policy.
SV-266281r1024756_ruleThe F5 BIG-IP appliance IPsec VPN Gateway must use Internet Key Exchange (IKE) for IPsec VPN Security Associations (SAs).
SV-266282r1024757_ruleThe IPsec BIG-IP appliance must use IKEv2 for IPsec VPN security associations.
SV-266283r1024758_ruleThe F5 BIG-IP appliance IPsec VPN Gateway must renegotiate the IPsec Phase 1 security association after eight hours or less.
SV-266284r1024759_ruleThe F5 BIG-IP appliance IPsec VPN must renegotiate the IKE Phase 2 security association after eight hours or less.
SV-266285r1024760_ruleFor accounts using password authentication, the F5 BIG-IP appliance site-to-site IPsec VPN Gateway must use SHA-2 or later protocol to protect the integrity of the password authentication process.
SV-266286r1024761_ruleThe F5 BIG-IP appliance IPsec VPN must use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
SV-266287r1024762_ruleThe F5 BIG-IP appliance IPsec VPN must be configured to use FIPS-validated SHA-2 or higher for Internet Key Exchange (IKE).
SV-266288r1024921_ruleThe F5 BIG-IP appliance IPsec VPN Gateway must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation.