STIGQter STIGQter: STIG Summary: Router Security Requirements Guide Version: 4 Release: 2 Benchmark Date: 23 Apr 2021:

The multicast Rendezvous Point (RP) router must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of Protocol Independent Multicast (PIM) and Multicast Source Discovery Protocol (MSDP) source-active entries.

DISA Rule

SV-207159r604135_rule

Vulnerability Number

V-207159

Group Title

SRG-NET-000362

Rule Version

SRG-NET-000362-RTR-000120

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure MSDP-enabled RP routers to limit the multicast forwarding cache for source-active entries.

Check Contents

Review the router configuration to determine if forwarding cache thresholds are defined.

If the RP router is not configured to limit the multicast forwarding cache to ensure that its resources are not saturated, this is a finding.

Vulnerability Number

V-207159

Documentable

False

Rule Version

SRG-NET-000362-RTR-000120

Severity Override Guidance

Review the router configuration to determine if forwarding cache thresholds are defined.

If the RP router is not configured to limit the multicast forwarding cache to ensure that its resources are not saturated, this is a finding.

Check Content Reference

M

Target Key

2917

Comments