{
"stig": {
"date": "2015-06-02",
"description": "This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.",
"findings": {
"V-59917": {
"checkid": "C-60605r1_chk",
"checktext": "If the BIG-IP AFM module is not used to support user access control intermediary services for virtual servers, this is not applicable.\n\nVerify the BIG-IP AFM module is configured to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.\n\nNavigate to the BIG-IP System manager >> Security >> Network Firewall >> Active Rules.\n\nVerify an active rule is configured to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.\n\nIf the BIG-IP AFM module is not configured to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic, this is a finding.",
"description": "Information flow control regulates where information is allowed to travel within a network. The flow of all network traffic must be monitored and controlled so it does not introduce any unacceptable risk to the network infrastructure or data.\n\nInformation flow control policies and enforcement mechanisms are commonly employed by organizations to control the flow of information between designated sources and destinations (e.g., networks, individuals, devices) within information systems. Examples of information flow control restrictions include keeping export-controlled information from being transmitted in the clear to the Internet or blocking information marked as classified but being transported to an unapproved destination.\n\nApplication Layer Gateways (ALGs) enforce approved authorizations by employing security policy and/or rules that restrict information system services, provide packet filtering capability based on header or protocol information and/or message filtering capability based on data content (e.g., implementing key word searches or using document characteristics).",
"fixid": "F-65325r1_fix",
"fixtext": "If the BIG-IP AFM module is used to support user access control intermediary services for virtual servers, configure the BIG-IP AFM module to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.",
"iacontrols": null,
"id": "V-59917",
"ruleID": "SV-74347r1_rule",
"severity": "medium",
"title": "The BIG-IP AFM module must be configured to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.",
"version": "F5BI-AF-000005"
},
"V-59921": {
"checkid": "C-60609r2_chk",
"checktext": "If the BIG-IP AFM module is not used to support user access control intermediary services for virtual servers, this is not applicable.\n\nVerify the BIG-IP AFM module is configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.\n\nNavigate to the BIG-IP System manager >> Security >> Network Firewall >> Active Rules.\n\nVerify an active rule is configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.\n\nIf the BIG-IP AFM module is not configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic, this is a finding.",
"description": "Information flow control regulates where information is allowed to travel within a network and between interconnected networks. Blocking or restricting detected harmful or suspicious communications between interconnected networks enforces approved authorizations for controlling the flow of traffic.\n\nThis requirement applies to the flow of information between the Application Layer Gateway (ALG) when used as a gateway or boundary device which allows traffic flow between interconnected networks of differing security policies.\n\nThe ALG installed and configured in such a way that restricts or blocks information flows based on guidance in the Ports, Protocols, & Services (PPSM) regarding restrictions for boundary crossing for ports, protocols, and services. Information flow restrictions may be implemented based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.\n\nThe ALGs must be configured with policy filters (e.g., security policy, rules, and/or signatures) that restrict or block information system services; provide a packet filtering capability based on header information; and/or perform message filtering based on message content. The policy filters used depend upon the type of application gateway (e.g., web, email, or TLS).",
"fixid": "F-65329r1_fix",
"fixtext": "If the BIG-IP AFM module is used to support user access control intermediary services for virtual servers, configure the BIG-IP AFM module to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.",
"iacontrols": null,
"id": "V-59921",
"ruleID": "SV-74351r1_rule",
"severity": "high",
"title": "The BIG-IP AFM module must be configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.",
"version": "F5BI-AF-000007"
},
"V-59923": {
"checkid": "C-60613r1_chk",
"checktext": "Verify the BIG-IP AFM module is configured to produce audit records containing information to establish what type of events occurred.\n\nNavigate to the BIG-IP System manager >> Security >> Event Logs >> Logging Profiles.\n\nVerify list of Profiles 'Enabled' for 'Network Firewall'.\n\nIf the BIG-IP AFM module does not produce audit records containing information to establish what type of events occurred, this is a finding.",
"description": "Without establishing what type of event occurred, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack.\n\nAudit record content that may be necessary to satisfy this requirement includes, for example, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked.\n\nAssociating event types with detected events in the gateway logs provides a means of investigating an attack, recognizing resource utilization or capacity thresholds, or identifying an improperly configured network element.\n\nThis requirement does not apply to audit logs generated on behalf of the device itself (management).",
"fixid": "F-65333r1_fix",
"fixtext": "Configure the BIG-IP AFM module to produce audit records containing information to establish what type of events occurred. \n\nNavigate to the BIG-IP System manager >> Security >> Event Logs >> Logging Profiles.\n\nClick on 'Create'.\n\nName the Profile.\n\nCheck the box next to 'Network Firewall'.\n\nConfigure settings to log required information.\n\nClick 'Finished'.",
"iacontrols": null,
"id": "V-59923",
"ruleID": "SV-74353r1_rule",
"severity": "medium",
"title": "The BIG-IP AFM module must be configured to produce audit records containing information to establish what type of events occurred.",
"version": "F5BI-AF-000039"
},
"V-59925": {
"checkid": "C-60615r1_chk",
"checktext": "If the BIG-IP AFM module is not used to support user access control intermediary services for virtual servers, this is not applicable.\n\nVerify the BIG-IP AFM module is configured to only allow incoming communications from authorized sources routed to authorized destinations.\n\nNavigate to the BIG-IP System manager >> Local Traffic >> Virtual Servers >> Virtual Servers List tab.\n\nSelect the applicable Virtual Servers(s) from the list to verify.\n\nNavigate to the Security >> Policies tab.\n\nVerify that \"Network Firewall\" is assigned a local Network Firewall Policy.\n\nVerify configuration of the identified Network Firewall policy:\n\nNavigate to the BIG-IP System manager >> Security >> Network Firewall >> Active Rules.\n\nSelect the Network Firewall policy that was assigned to the Virtual Server.\n\nReview the configuration of the \"Protocol\", \"Source\", \"Destination\", and \"Action\" sections at a minimum to ensure that the policy is only allowing incoming communications from authorized sources enroute to authorized destinations.\n\nIf the BIG-IP AFM module is not configured to only allow incoming communications from unauthorized sources routed to unauthorized destinations, this is a finding.",
"description": "Unrestricted traffic may contain malicious traffic that poses a threat to an enclave or to other connected networks. Additionally, unrestricted traffic may transit a network, which uses bandwidth and other resources.\n\nAccess control policies and access control lists implemented on devices that control the flow of network traffic (e.g., application-level firewalls and Web content filters) ensure the flow of traffic is only allowed from authorized sources to authorized destinations. Networks with different levels of trust (e.g., the Internet or CDS) must be kept separate.",
"fixid": "F-65335r1_fix",
"fixtext": "Configure the BIG-IP AFM module to only allow incoming communications from authorized sources routed to authorized destinations.",
"iacontrols": null,
"id": "V-59925",
"ruleID": "SV-74355r1_rule",
"severity": "medium",
"title": "The BIG-IP AFM module must be configured to only allow incoming communications from authorized sources routed to authorized destinations.",
"version": "F5BI-AF-000223"
},
"V-59927": {
"checkid": "C-60617r2_chk",
"checktext": "Verify the BIG-IP AFM module is configured to handle invalid input in a predictable and documented manner that reflects organizational and system objectives.\n\nThis can be demonstrated by the SA sending an invalid input to a virtual server. Provide evidence that the virtual server was able to handle the invalid input and maintain operation.\n\nIf the BIG-IP AFM module is not configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives, this is a finding.",
"description": "A common vulnerability of network elements is unpredictable behavior when invalid inputs are received. This requirement guards against adverse or unintended system behavior caused by invalid inputs where information system responses to the invalid input may be disruptive or cause the system to fail into an unsafe state.\n\nThe behavior will be derived from the organizational and system requirements and includes, but is not limited to, notification of the appropriate personnel, creating an audit record, and rejecting invalid input.\n\nThis requirement applies to gateways and firewalls that perform content inspection or have higher layer proxy functions.",
"fixid": "F-65337r1_fix",
"fixtext": "Configure the BIG-IP AFM module to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.",
"iacontrols": null,
"id": "V-59927",
"ruleID": "SV-74357r1_rule",
"severity": "medium",
"title": "The BIG-IP AFM module must be configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.",
"version": "F5BI-AF-000229"
}
},
"profiles": {
"MAC-1_Classified": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-1_Classified",
"title": "I - Mission Critical Classified"
},
"MAC-1_Public": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-1_Public",
"title": "I - Mission Critical Public"
},
"MAC-1_Sensitive": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-1_Sensitive",
"title": "I - Mission Critical Sensitive"
},
"MAC-2_Classified": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-2_Classified",
"title": "II - Mission Support Classified"
},
"MAC-2_Public": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-2_Public",
"title": "II - Mission Support Public"
},
"MAC-2_Sensitive": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-2_Sensitive",
"title": "II - Mission Support Sensitive"
},
"MAC-3_Classified": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-3_Classified",
"title": "III - Administrative Classified"
},
"MAC-3_Public": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-3_Public",
"title": "III - Administrative Public"
},
"MAC-3_Sensitive": {
"description": "",
"findings": {
"V-59917": "true",
"V-59921": "true",
"V-59923": "true",
"V-59925": "true",
"V-59927": "true"
},
"id": "MAC-3_Sensitive",
"title": "III - Administrative Sensitive"
}
},
"slug": "f5_big-ip_advanced_firewall_manager_11.x",
"title": "F5 BIG-IP Advanced Firewall Manager 11.x Security Technical Implementation Guide",
"version": "1"
}
}