STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 1 hour ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to F5 BIG-IP TMOS ALG Security Technical Implementation Guide

V-266174

CAT II (Medium)

The VPN Gateway must use Always On VPN connections for remote computing.

Rule ID

SV-266174r1024406_rule

STIG

F5 BIG-IP TMOS ALG Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-000366CCI-001184

Discussion

Allowing remote users to manually toggle a VPN connection can create critical security risks. With Always On VPN, if a secured connection to the gateway is lost, hybrid-working users will simply be disconnected from the internet until the issue is solved. "Always On" is a term that describes a VPN connection that is secure and always on after the initial connection is established. An Always On VPN deployment establishes a VPN connection with the client without the need for user interaction (e.g., user credentials). The remote client must not be able to access the Internet without first established a VPN session with a DOD site. Note that device compliance checks are still required prior to connecting to DOD resources. Although out of scope for this requirement, the connection process must ensure that remote devices meet security standards before accessing DOD resources. Devices that fail to meet compliance requirements can be denied access, reducing the risk of compromised endpoints.

Check Content

Verify at least one of these methods is configured.

Always Connected Mode:
From the BIG-IP GUI:
1. Access.
2. Connectivity/VPN.
3. Connectivity.
4. Profiles.
5. Click the name of the profile.
6. At the bottom, click Customize Package >> Windows.
7. Click "BIG-IP Edge Client" on the left.
8. Verify "Enable Always connected mode" is enabled.

Machine Tunnels:
From the BIG-IP GUI:
1. Access.
2. Connectivity/VPN.
3. Connectivity.
4. Profiles.
5. Click the name of the profile.
6. At the bottom, click Customize Package >> Windows.
7. Verify "Machine Tunnel Service" is checked.

If the BIG-IP VPN Gateway is not configured to use an Always On VPN connection for remote computing, this is a finding.

Fix Text

Configure at least one of these methods.
Always Connected Mode:

From the BIG-IP GUI:
1. Access.
2. Connectivity/VPN.
3. Connectivity.
4. Profiles.
5. Click the name of the profile.
6. At the bottom, click Customize Package >> Windows.
7. Click "BIG-IP Edge Client" on the left.
8. Check the box next to "Enable Always connected mode".
Note: Always connected mode requires at least one host be listed in the Server list of the Connectivity Profile. Edit the Connectivity Profile to add an entry, if necessary.
9. Click "Download" to save the settings and download the installer.

Machine Tunnels:
From the BIG-IP GUI:
1. Access.
2. Connectivity/VPN.
3. Connectivity.
4. Profiles.
5. Click the name of the profile.
6. At the bottom, click Customize Package >> Windows.
7. Check "Machine Tunnel Service".
8. Optionally, click "Machine Tunnel Service" on the left and check "Enable NLA for Machine Tunnel".
Note: To configure DNS Suffixes for NLA, edit the Connectivity Profile >> Win/Mac Edge Client > Location DNS List.
9. Click "Download" to save the settings and download the installer.