SV-220995r1107540_rule
V-220995
SRG-NET-000362-RTR-000110
CISC-RT-000120
CAT I
10
Configure the Cisco switch to protect against known types of DoS attacks on the route processor.
Step 1: Configure the default policer rates for all control plane CPU queues and save the configuration.
Device> enable
Device# configure terminal
Device(config)# cpp system-default
Defaulting CPP : Policer rate for all classes will be set to their defaults
Device(config)# end
Device# copy running-configuration startup-configuration
Step 2: View the policy map and verify the correct policer rates are set according to organization-defined standards.
show policy-map control-plane
Step 3: Change any policer rates to match the organization-defined standards.
Note: Starting from Cisco IOS XE Fuji 16.8.1a, the creation of user-defined class-maps is not supported. A user can only enable/disable a CPU queue or change the policer rate of a CPU queue.
Review the Cisco switch configuration to verify it is compliant with this requirement.
Step 1: To verify that the CoPP policy map has been saved, issue the "show running-config" command in privileged EXEC mode and verify the following line exists in the output:
policy-map system-cpp-policy
Step 2: To view the policy map and verify the correct policer rates are set according to organization-defined standards, run the following command:
show policy-map control-plane
Note: Starting from Cisco IOS XE Fuji 16.8.1a, the creation of user-defined class-maps is not supported. A user can only enable/disable a CPU queue or change the policer rate of a CPU queue.
If the Cisco switch is not configured to protect against known types of DoS attacks by employing organization-defined security safeguards, this is a finding.
V-220995
False
CISC-RT-000120
Review the Cisco switch configuration to verify it is compliant with this requirement.
Step 1: To verify that the CoPP policy map has been saved, issue the "show running-config" command in privileged EXEC mode and verify the following line exists in the output:
policy-map system-cpp-policy
Step 2: To view the policy map and verify the correct policer rates are set according to organization-defined standards, run the following command:
show policy-map control-plane
Note: Starting from Cisco IOS XE Fuji 16.8.1a, the creation of user-defined class-maps is not supported. A user can only enable/disable a CPU queue or change the policer rate of a CPU queue.
If the Cisco switch is not configured to protect against known types of DoS attacks by employing organization-defined security safeguards, this is a finding.
M
4074