F5BI-DM-300001 - The F5 BIG-IP appliance must be configured to limit the number of concurrent sessions to the Configuration Utility to 10 or an organization-defined number.

Information

Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administrator is helpful in limiting risks related to denial-of-service (DoS) attacks.

This requirement addresses concurrent sessions for administrative accounts and does not address concurrent sessions by a single administrator via multiple administrative accounts.

Satisfies: SRG-APP-000001-NDM-000200, SRG-APP-000435-NDM-000315

Solution

From the BIG-IP GUI:
1. System.
2. Preferences.
3. Set System Settings view to Advanced.
4. Maximum HTTP connections to Configuration Utility: enter 10 or an organization-defined number.
5. Update.

From the BIG-IP console, type the following commands:

tmsh modify sys httpd max-clients <10 or an organization-defined number>
tmsh save sys config

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_F5_BIG-IP_TMOS_Y25M07_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-10, 800-53|SC-5, CAT|II, CCI|CCI-000054, CCI|CCI-002385, Rule-ID|SV-266064r1024595_rule, STIG-ID|F5BI-DM-300001, Vuln-ID|V-266064

Plugin: F5

Control ID: 52b33d735923770f8b47cf0e902775ec713a32d98fb249f972b9268a26b445d4