STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to F5 BIG-IP TMOS Firewall Security Technical Implementation Guide

V-266263

CAT II (Medium)

The F5 BIG-IP appliance must be configured to inspect all inbound and outbound traffic at the application layer.

Rule ID

SV-266263r1024879_rule

STIG

F5 BIG-IP TMOS Firewall Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000366

Discussion

Application inspection enables the firewall to control traffic based on different parameters that exist within the packets such as enforcing application-specific message and field length. Inspection provides improved protection against application-based attacks by restricting the types of commands allowed for the applications. Application inspection all enforces conformance against published RFCs. Some applications embed an IP address in the packet that needs to match the source address that is normally translated when it goes through the firewall. Enabling application inspection for a service that embeds IP addresses, the firewall translates embedded addresses and updates any checksum or other fields that are affected by the translation. Enabling application inspection for a service that uses dynamically assigned ports, the firewall monitors sessions to identify the dynamic port assignments and permits data exchange on these ports for the duration of the specific session.

Check Content

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>

If configured rules in the policy do not use packet headers and packet attributes, including source and destination IP addresses and ports to inspect all inbound and outbound traffic at the application layer, this is a finding.

Fix Text

From the BIG-IP GUI:
1. Security.
2. Network Firewall.
3. Policies.
4. <Policy Name>
5. Configure rules to use packet headers and packet attributes, including source and destination IP addresses and ports inspect all inbound and outbound traffic at the application layer.