1. Home
  2. Security Hardening
  3. Tenable F5 Big IP Best Practice
  4. Configuring CIDR Network Addresses for the BIG-IP packet filter – Always accept important ICMP

Configuring CIDR Network Addresses for the BIG-IP packet filter – Always accept important ICMP

Details

You can use the BIG-IP packet filter functionality to enhance network security by enforcing an access policy on traffic ingressing or egressing a VLAN on the BIG-IP system. You must configure packet filter functionality to block CIDR network addresses from the TMOS Shell.

Solution

Log in to tmsh by typing the following command:
tmsh
2. modify /sys db packetfilter.allow.important.icmp value

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system F5.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles