SV-253979r843970_rule
V-253979
SRG-NET-000018-RTR-000007
JUEX-RT-000070
CAT III
10
Configure the MSDP router to implement an import policy to block multicast advertisements for undesirable multicast groups and sources.
set protocols msdp peer <address> import source-active-filter
set policy-options policy-statement source-active-filter term unauth-groups from route-filter 224.0.1.2/32 exact
set policy-options policy-statement source-active-filter term unauth-groups from route-filter 224.0.2.2/32 exact
set policy-options policy-statement source-active-filter term unauth-groups then reject
set policy-options policy-statement source-active-filter term unauth-sources from source-address-filter 10.0.0.0/8 orlonger
set policy-options policy-statement source-active-filter term unauth-sources from source-address-filter 127.0.0.0/8 orlonger
set policy-options policy-statement source-active-filter term unauth-sources then reject
Review the router configuration to determine if there is an import policy to block source-active multicast advertisements for any undesirable multicast groups, as well as any (S, G) states with undesirable source addresses.
Verify that an inbound source-active filter is bound to each MSDP peer.
[edit protocols msdp]
peer <address> {
import source-active-filter;
}
Review the policy-statement referenced by the source-active filter to verify that undesirable multicast groups, auto-RP, single source multicast (SSM) groups, and advertisements from undesirable sources are blocked.
[edit policy-options]
policy-statement source-active-filter {
term unauth-groups {
from {
route-filter 224.0.1.2/32 exact;
route-filter 224.0.2.2/32 exact;
}
then reject;
}
term unauth-sources {
from {
source-address-filter 10.0.0.0/8 orlonger;
source-address-filter 127.0.0.0/8 orlonger;
}
then reject;
}
}
If the router is not configured with an import policy to block undesirable SA multicast advertisements, this is a finding.
V-253979
False
JUEX-RT-000070
Review the router configuration to determine if there is an import policy to block source-active multicast advertisements for any undesirable multicast groups, as well as any (S, G) states with undesirable source addresses.
Verify that an inbound source-active filter is bound to each MSDP peer.
[edit protocols msdp]
peer <address> {
import source-active-filter;
}
Review the policy-statement referenced by the source-active filter to verify that undesirable multicast groups, auto-RP, single source multicast (SSM) groups, and advertisements from undesirable sources are blocked.
[edit policy-options]
policy-statement source-active-filter {
term unauth-groups {
from {
route-filter 224.0.1.2/32 exact;
route-filter 224.0.2.2/32 exact;
}
then reject;
}
term unauth-sources {
from {
source-address-filter 10.0.0.0/8 orlonger;
source-address-filter 127.0.0.0/8 orlonger;
}
then reject;
}
}
If the router is not configured with an import policy to block undesirable SA multicast advertisements, this is a finding.
M
5479