CIS F5 BIG-IP Benchmark

Secure configuration guidelines for F5 BIG-IP application delivery controller

v1.1.0 November 2024

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for F5 BIG-IP. Recommendations cover system configuration, user authentication and access control, network security, SSL/TLS profiles, logging and monitoring, and high availability hardening.

~110Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1SystemHostname, NTP, platform
2AuthenticationUsers, RBAC, remote auth
3NetworkSelf IPs, VLANs, SSH
4SSL/TLSCiphers, PFS, profiles
5LoggingSyslog, audit, SNMP
6HAFailover, backup, sync

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all F5 BIG-IP deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — System Configuration

▶

1.1 General Settings

▶
1.1.1 Ensure Device Hostname Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Device Hostname Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Device Hostname Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Device Hostname Is Configured. Apply the setting via CLI or management GUI and save the configuration.

1.1.2 Ensure Management IP Access Is Restricted (Automated)
L1 Auto
Description

This setting ensures that Management IP Access Is Restricted on the F5 BIG-IP application delivery controller. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the F5 BIG-IP application delivery controller is essential for defense in depth.

Audit

Review the F5 BIG-IP device configuration and verify that Management IP Access Is Restricted. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Management IP Access Is Restricted. Apply the setting via CLI or management GUI and save the configuration.

1.1.3 Ensure NTP Is Configured with Authenticated Sources (Automated)
L1 Auto
Description

This recommendation verifies that NTP Is Configured with Authenticated Sources on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that NTP Is Configured with Authenticated Sources. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure NTP Is Configured with Authenticated Sources. Apply the setting via CLI or management GUI and save the configuration.

1.1.4 Ensure Banner Is Configured for Login Screens (Automated)
L1 Auto
Description

This recommendation verifies that Banner Is Configured for Login Screens on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Banner Is Configured for Login Screens. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Banner Is Configured for Login Screens. Apply the setting via CLI or management GUI and save the configuration.

1.2 Platform Hardening

▶
1.2.1 Ensure TMOS Is Running Latest Hotfix Version (Manual)
L1 Manual
Description

This recommendation verifies that TMOS Is Running Latest Hotfix Version on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that TMOS Is Running Latest Hotfix Version. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure TMOS Is Running Latest Hotfix Version. Apply the setting via CLI or management GUI and save the configuration.

1.2.2 Ensure Unnecessary Modules Are Deprovisioned (Manual)
L1 Manual
Description

This recommendation verifies that Unnecessary Modules Are Deprovisioned on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Unnecessary Modules Are Deprovisioned. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Unnecessary Modules Are Deprovisioned. Apply the setting via CLI or management GUI and save the configuration.

1.2.3 Ensure iApps LX Packages Are Reviewed (Manual)
L2 Manual
Description

This recommendation verifies that iApps LX Packages Are Reviewed on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that iApps LX Packages Are Reviewed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure iApps LX Packages Are Reviewed. Apply the setting via CLI or management GUI and save the configuration.

1.2.4 Ensure Console Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Console Timeout Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Console Timeout Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Console Timeout Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2 — Authentication & Access Control

▶

2.1 User Accounts

▶
2.1.1 Ensure Default Admin Password Is Changed (Manual)
L1 Manual
Description

This recommendation verifies that Default Admin Password Is Changed on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Default Admin Password Is Changed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Default Admin Password Is Changed. Apply the setting via CLI or management GUI and save the configuration.

2.1.2 Ensure Root Account Is Disabled for Remote Access (Automated)
L1 Auto
Description

This recommendation verifies that Root Account Is Disabled for Remote Access on the F5 BIG-IP application delivery controller. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the F5 BIG-IP application delivery controller increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Review the F5 BIG-IP device configuration and verify that Root Account Is Disabled for Remote Access. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Root Account Is Disabled for Remote Access. Apply the setting via CLI or management GUI and save the configuration.

2.1.3 Ensure Strong Password Policy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Strong Password Policy Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Strong Password Policy Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Strong Password Policy Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2.1.4 Ensure Role-Based Access Control Is Configured (Manual)
L1 Manual
Description

This recommendation verifies that Role-Based Access Control Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Role-Based Access Control Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Role-Based Access Control Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2.2 Remote Authentication

▶
2.2.1 Ensure RADIUS or TACACS+ Authentication Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that RADIUS or TACACS+ Authentication Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that RADIUS or TACACS+ Authentication Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure RADIUS or TACACS+ Authentication Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2.2.2 Ensure Remote Authentication Fallback Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Remote Authentication Fallback Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Remote Authentication Fallback Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Remote Authentication Fallback Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2.2.3 Ensure Account Lockout Policy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Account Lockout Policy Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Account Lockout Policy Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Account Lockout Policy Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2.2.4 Ensure Idle Session Timeout Is Set (Automated)
L1 Auto
Description

This recommendation verifies that Idle Session Timeout Is Set on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Idle Session Timeout Is Set. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Idle Session Timeout Is Set. Apply the setting via CLI or management GUI and save the configuration.

3 — Network Security

▶

3.1 Self IP & VLAN Configuration

▶
3.1.1 Ensure Self IP Port Lockdown Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Self IP Port Lockdown Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Self IP Port Lockdown Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Self IP Port Lockdown Is Configured. Apply the setting via CLI or management GUI and save the configuration.

3.1.2 Ensure Management VLAN Is Isolated (Automated)
L1 Auto
Description

This recommendation verifies that Management VLAN Is Isolated on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Management VLAN Is Isolated. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Management VLAN Is Isolated. Apply the setting via CLI or management GUI and save the configuration.

3.1.3 Ensure SNAT Pools Are Configured Appropriately (Manual)
L1 Manual
Description

This recommendation verifies that SNAT Pools Are Configured Appropriately on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that SNAT Pools Are Configured Appropriately. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure SNAT Pools Are Configured Appropriately. Apply the setting via CLI or management GUI and save the configuration.

3.2 Protocol & Service Security

▶
3.2.1 Ensure SSH Access Is Restricted to Management Interface (Automated)
L1 Auto
Description

This setting ensures that SSH Access Is Restricted to Management Interface on the F5 BIG-IP application delivery controller. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the F5 BIG-IP application delivery controller is essential for defense in depth.

Audit

Review the F5 BIG-IP device configuration and verify that SSH Access Is Restricted to Management Interface. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure SSH Access Is Restricted to Management Interface. Apply the setting via CLI or management GUI and save the configuration.

3.2.2 Ensure HTTPD Is Disabled on Data Interfaces (Automated)
L1 Auto
Description

This recommendation verifies that HTTPD Is Disabled on Data Interfaces on the F5 BIG-IP application delivery controller. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the F5 BIG-IP application delivery controller increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Review the F5 BIG-IP device configuration and verify that HTTPD Is Disabled on Data Interfaces. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure HTTPD Is Disabled on Data Interfaces. Apply the setting via CLI or management GUI and save the configuration.

3.2.3 Ensure SNMP Community Strings Are Changed (Automated)
L1 Auto
Description

This recommendation verifies that SNMP Community Strings Are Changed on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that SNMP Community Strings Are Changed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure SNMP Community Strings Are Changed. Apply the setting via CLI or management GUI and save the configuration.

3.2.4 Ensure SNMPv3 Is Used (Automated)
L2 Auto
Description

This recommendation verifies that SNMPv3 Is Used on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that SNMPv3 Is Used. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure SNMPv3 Is Used. Apply the setting via CLI or management GUI and save the configuration.

4 — SSL / TLS Profiles

▶

4.1 Client SSL Profiles

▶
4.1.1 Ensure TLS 1.2 Is the Minimum Version (Automated)
L1 Auto
Description

This recommendation verifies that TLS 1.2 Is the Minimum Version on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that TLS 1.2 Is the Minimum Version. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure TLS 1.2 Is the Minimum Version. Apply the setting via CLI or management GUI and save the configuration.

4.1.2 Ensure Weak Cipher Suites Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Weak Cipher Suites Are Disabled on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Weak Cipher Suites Are Disabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Weak Cipher Suites Are Disabled. Apply the setting via CLI or management GUI and save the configuration.

4.1.3 Ensure Perfect Forward Secrecy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Perfect Forward Secrecy Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Perfect Forward Secrecy Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Perfect Forward Secrecy Is Configured. Apply the setting via CLI or management GUI and save the configuration.

4.1.4 Ensure Certificate Chain Is Complete (Manual)
L1 Manual
Description

This recommendation verifies that Certificate Chain Is Complete on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Certificate Chain Is Complete. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Certificate Chain Is Complete. Apply the setting via CLI or management GUI and save the configuration.

4.2 Server SSL Profiles

▶
4.2.1 Ensure Backend TLS Verification Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Backend TLS Verification Is Enabled on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Backend TLS Verification Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Backend TLS Verification Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

4.2.2 Ensure Server Certificate Is Validated (Automated)
L2 Auto
Description

This recommendation verifies that Server Certificate Is Validated on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Server Certificate Is Validated. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Server Certificate Is Validated. Apply the setting via CLI or management GUI and save the configuration.

4.2.3 Ensure SSL Session Caching Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that SSL Session Caching Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that SSL Session Caching Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure SSL Session Caching Is Configured. Apply the setting via CLI or management GUI and save the configuration.

5 — Logging & Monitoring

▶

5.1 Logging Configuration

▶
5.1.1 Ensure Remote Syslog Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Remote Syslog Is Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Remote Syslog Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Remote Syslog Is Configured. Apply the setting via CLI or management GUI and save the configuration.

5.1.2 Ensure Audit Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Audit Logging Is Enabled on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Audit Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Audit Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

5.1.3 Ensure Log Severity Levels Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Log Severity Levels Are Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Log Severity Levels Are Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Log Severity Levels Are Configured. Apply the setting via CLI or management GUI and save the configuration.

5.1.4 Ensure MCP Logging Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that MCP Logging Is Enabled on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that MCP Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure MCP Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

5.2 Monitoring & Alerting

▶
5.2.1 Ensure SNMP Traps Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that SNMP Traps Are Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that SNMP Traps Are Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure SNMP Traps Are Configured. Apply the setting via CLI or management GUI and save the configuration.

5.2.2 Ensure iHealth Diagnostics Are Reviewed Periodically (Manual)
L2 Manual
Description

This recommendation verifies that iHealth Diagnostics Are Reviewed Periodically on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that iHealth Diagnostics Are Reviewed Periodically. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure iHealth Diagnostics Are Reviewed Periodically. Apply the setting via CLI or management GUI and save the configuration.

5.2.3 Ensure System Alerts Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that System Alerts Are Configured on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that System Alerts Are Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure System Alerts Are Configured. Apply the setting via CLI or management GUI and save the configuration.

6 — High Availability & Resilience

▶

6.1 HA Configuration

▶
6.1.1 Ensure Device Group Is Configured for Failover (Manual)
L1 Manual
Description

This recommendation verifies that Device Group Is Configured for Failover on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Device Group Is Configured for Failover. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Device Group Is Configured for Failover. Apply the setting via CLI or management GUI and save the configuration.

6.1.2 Ensure Config Sync Is Encrypted (Automated)
L2 Auto
Description

This recommendation verifies that Config Sync Is Encrypted on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Config Sync Is Encrypted. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Config Sync Is Encrypted. Apply the setting via CLI or management GUI and save the configuration.

6.1.3 Ensure Mirroring Uses Dedicated VLAN (Automated)
L2 Auto
Description

This recommendation verifies that Mirroring Uses Dedicated VLAN on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Mirroring Uses Dedicated VLAN. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Mirroring Uses Dedicated VLAN. Apply the setting via CLI or management GUI and save the configuration.

6.2 Backup & Recovery

▶
6.2.1 Ensure UCS Archives Are Created and Stored Securely (Manual)
L1 Manual
Description

This recommendation verifies that UCS Archives Are Created and Stored Securely on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that UCS Archives Are Created and Stored Securely. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure UCS Archives Are Created and Stored Securely. Apply the setting via CLI or management GUI and save the configuration.

6.2.2 Ensure Configuration Is Regularly Backed Up (Manual)
L1 Manual
Description

This recommendation verifies that Configuration Is Regularly Backed Up on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Configuration Is Regularly Backed Up. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Configuration Is Regularly Backed Up. Apply the setting via CLI or management GUI and save the configuration.

6.2.3 Ensure Master Key Is Backed Up Securely (Manual)
L1 Manual
Description

This recommendation verifies that Master Key Is Backed Up Securely on the F5 BIG-IP application delivery controller. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the F5 BIG-IP application delivery controller vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the F5 BIG-IP device configuration and verify that Master Key Is Backed Up Securely. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the F5 BIG-IP device configuration to ensure Master Key Is Backed Up Securely. Apply the setting via CLI or management GUI and save the configuration.