STIGQter STIGQter: STIG Summary: Router Security Requirements Guide Version: 4 Release: 2 Benchmark Date: 23 Apr 2021:

The BGP router must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.

DISA Rule

SV-207138r604135_rule

Vulnerability Number

V-207138

Group Title

SRG-NET-000205

Rule Version

SRG-NET-000205-RTR-000006

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure all eBGP routers to filter outbound route advertisements belonging to the IP core.

Check Contents

Review the router configuration to verify that there is a filter defined to block route advertisements for prefixes that belong to the IP core.

The prefix filter must be referenced outbound on the appropriate BGP neighbor statements.

If the router is not configured to reject outbound route advertisements that belong to the IP core, this is a finding.

Vulnerability Number

V-207138

Documentable

False

Rule Version

SRG-NET-000205-RTR-000006

Severity Override Guidance

Review the router configuration to verify that there is a filter defined to block route advertisements for prefixes that belong to the IP core.

The prefix filter must be referenced outbound on the appropriate BGP neighbor statements.

If the router is not configured to reject outbound route advertisements that belong to the IP core, this is a finding.

Check Content Reference

M

Target Key

2917

Comments