F5 BIG-IP TMOS VPN Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- F5BI-VN-300004
- Vuln IDs
-
- V-266277
- Rule IDs
-
- SV-266277r1024911_rule
Checks: C-70201r1024909_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the IKE Peer Name. 5. In "IKE Phase 1 Algorithms", verify "MODP4096" or higher is selected for "Perfect Forward Secrecy". If the BIG-IP appliance is not configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1, this is a finding.
Fix: F-70104r1024910_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the IKE Peer Name. 5. In "IKE Phase 1 Algorithms", select "MODP4096" or higher for "Perfect Forward Secrecy". 6. Click "Update".
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- F5BI-VN-300005
- Vuln IDs
-
- V-266278
- Rule IDs
-
- SV-266278r1024913_rule
Checks: C-70202r1024080_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the Name of the IKE peer. 5. Verify an AES256 encryption algorithm is selected under IKE Phase 1 Algorithms >> Encryption Algorithm. If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IKE proposal, this is a finding.
Fix: F-70105r1024912_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the Name of the IKE peer. 5. Configure an AES256 encryption algorithm under IKE Phase 1 Algorithms >> Encryption Algorithm. 6. Click "Update".
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- F5BI-VN-300006
- Vuln IDs
-
- V-266279
- Rule IDs
-
- SV-266279r1024915_rule
Checks: C-70203r1024083_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the Name of the IPsec Policy. 5. Verify an AES256 or greater encryption algorithm is selected. If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IPsec proposal, this is a finding.
Fix: F-70106r1024914_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Configure AES256 or greater encryption algorithm. 6. Click "Update".
- RMF Control
- AC-4
- Severity
- H
- CCI
- CCI-001414
- Version
- F5BI-VN-300009
- Vuln IDs
-
- V-266280
- Rule IDs
-
- SV-266280r1024917_rule
Checks: C-70204r1024086_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on IPsec Policy for site to site IPsec. 5. Verify that "ESP" is selected in the IPsec Protocol section. If the BIG-IP is not configured to ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies, this is a finding.
Fix: F-70107r1024916_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on IPsec Policy for site to site IPsec. 5. Select "ESP" in the IPsec Protocol section. 6. Click "Update".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- F5BI-VN-300021
- Vuln IDs
-
- V-266281
- Rule IDs
-
- SV-266281r1024756_rule
Checks: C-70205r1024089_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. Manual Security Associations. 4. Verify there are no Manual Security Associations listed. If the BIG-IP appliance is not configured to use IKE for IPsec VPN SAs, this is a finding.
Fix: F-70108r1024090_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. Manual Security Associations. 4. Delete any entries in this list.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- F5BI-VN-300024
- Vuln IDs
-
- V-266282
- Rule IDs
-
- SV-266282r1024757_rule
Checks: C-70206r1024092_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the name of the IKE peer. 5. Verify "Version 2" is selected for "Version". If the BIG-IP appliance is not configured to use IKEv2 for IPsec VPN security associations, this is a finding.
Fix: F-70109r1024093_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the name of the IKE peer. 5. Select "Version 2" for "Version". 6. Click "Update".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- F5BI-VN-300025
- Vuln IDs
-
- V-266283
- Rule IDs
-
- SV-266283r1024758_rule
Checks: C-70207r1024095_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the Name of the IKE peer. 5. Verify that the value for "Lifetime" under "IKE Phase 1 Algorithms" is set to 480 minutes or less, or an organization-defined time period. If the BIG-IP appliance is not configured to renegotiate the security association after 8 hours or less, or an organization-defined period, this is a finding.
Fix: F-70110r1024096_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the Name of the IKE peer. 5. Configure the value for "Lifetime" under "IKE Phase 1 Algorithms" to 480 minutes or less, or an organization-defined time period. 6. Click "Update".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- F5BI-VN-300026
- Vuln IDs
-
- V-266284
- Rule IDs
-
- SV-266284r1024759_rule
Checks: C-70208r1024098_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Verify that the value for "Lifetime" under "IKE Phase 2" is set to 480 minutes or less. If the BIG-IP appliance is not configured to renegotiate the security association after 8 hours or less, this is a finding.
Fix: F-70111r1024099_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Configure the value for "Lifetime" under "IKE Phase 2" to 480 minutes or less. 6. Click "Update".
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000197
- Version
- F5BI-VN-300033
- Vuln IDs
-
- V-266285
- Rule IDs
-
- SV-266285r1024760_rule
Checks: C-70209r1024101_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the Name of the IKE peer. 5. Verify that the value for "Authentication Algorithm" under "IKE Phase 1 Algorithms" is set to "SHA-256" or higher. If the BIG-IP appliance is not configured to use SHA-2 or later protocol to protect the integrity of the password authentication process, this is a finding.
Fix: F-70112r1024102_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the Name of the IKE peer. 5. Configure the value for "Authentication Algorithm" under "IKE Phase 1 Algorithms" to "SHA-256" or higher. 6. Click "Update".
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- F5BI-VN-300040
- Vuln IDs
-
- V-266286
- Rule IDs
-
- SV-266286r1024761_rule
Checks: C-70210r1024104_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the name of the IKE peer. 5. Verify that "IKE Phase 1 Algorithms" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network. From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Verify that "IKE Phase 2" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network. If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network, this is a finding.
Fix: F-70113r1024105_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the name of the IKE peer. 5. Configure "IKE Phase 1 Algorithms" to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network. 6. Click "Update". From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Configure "IKE Phase 2" to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network. 6. Click "Update".
- RMF Control
- SC-23
- Severity
- H
- CCI
- CCI-001184
- Version
- F5BI-VN-300041
- Vuln IDs
-
- V-266287
- Rule IDs
-
- SV-266287r1024762_rule
Checks: C-70211r1024107_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the name of the IKE peer. 5. Verify "SHA-1" or "MD5" is not selected for the following: IKE Phase 1 Algorithms >> Authentication Algorithm IKE Phase 1 Algorithms >> Pseudo-Random Function From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click the name of the IPsec Policy. 5. Verify "SHA-1" is not selected for the following: IKE Phase 2 >> Authentication Algorithm If the BIG-IP appliance is not configured to use FIPS-validated SHA-2 or higher for IKE, this is a finding.
Fix: F-70114r1024108_fix
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IKE Peers. 4. Click on the name of the IKE peer. 5. Configure SHA-2 or higher for the following: IKE Phase 1 Algorithms >> Authentication Algorithm IKE Phase 1 Algorithms >> Pseudo-Random Function 6. Click "Update". From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click the name of the IPsec Policy. 5. Configure SHA-2 or higher for the following: IKE Phase 2 >> Authentication Algorithm 6. Click "Update".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- F5BI-VN-300044
- Vuln IDs
-
- V-266288
- Rule IDs
-
- SV-266288r1024921_rule
Checks: C-70212r1024110_chk
From the BIG-IP GUI: 1. Network. 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Verify "NONE" is not selected in "IKE Phase 2 >> Perfect Forward Secrecy". If the BIG-IP appliance is not configured to specify PFS during IKE negotiation, this is a finding.
Fix: F-70115r1024111_fix
From the BIG-IP GUI: 1. Network 2. IPsec. 3. IPsec Policies. 4. Click on the name of the IPsec Policy. 5. Select any value other than "NONE" in "IKE Phase 2 >> Perfect Forward Secrecy". 6. Click "Update".