SV-253980r843973_rule
V-253980
SRG-NET-000018-RTR-000008
JUEX-RT-000080
CAT III
10
Ensure an export policy is implemented on all MSDP routers to avoid global visibility of local multicast (S, G) states.
set protocols msdp peer <address> export source-active-filter
set policy-options policy-statement source-active-filter term unauth-groups from route-filter 224.0.1.2/32 exact
set policy-options policy-statement source-active-filter term unauth-groups from route-filter 224.0.2.2/32 exact
set policy-options policy-statement source-active-filter term unauth-groups then reject
set policy-options policy-statement source-active-filter term unauth-sources from source-address-filter 10.0.0.0/8 orlonger
set policy-options policy-statement source-active-filter term unauth-sources from source-address-filter 127.0.0.0/8 orlonger
set policy-options policy-statement source-active-filter term unauth-sources then reject
Review the router configuration to determine if there is export policy to block local source-active multicast advertisements.
Verify that an outbound source-active filter is bound to each MSDP peer.
[edit protocols msdp]
peer <address> {
export source-active-filter;
}
Review the policy-statement referenced by the source-active filters and verify that MSDP source-active messages being sent to MSDP peers do not leak advertisements that are local.
[edit policy-options]
policy-statement source-active-filter {
term unauth-groups {
from {
route-filter 224.0.1.2/32 exact;
route-filter 224.0.2.2/32 exact;
}
then reject;
}
term unauth-sources {
from {
source-address-filter 10.0.0.0/8 orlonger;
source-address-filter 127.0.0.0/8 orlonger;
}
then reject;
}
}
If the router is not configured with an export policy to block local source-active multicast advertisements, this is a finding.
V-253980
False
JUEX-RT-000080
Review the router configuration to determine if there is export policy to block local source-active multicast advertisements.
Verify that an outbound source-active filter is bound to each MSDP peer.
[edit protocols msdp]
peer <address> {
export source-active-filter;
}
Review the policy-statement referenced by the source-active filters and verify that MSDP source-active messages being sent to MSDP peers do not leak advertisements that are local.
[edit policy-options]
policy-statement source-active-filter {
term unauth-groups {
from {
route-filter 224.0.1.2/32 exact;
route-filter 224.0.2.2/32 exact;
}
then reject;
}
term unauth-sources {
from {
source-address-filter 10.0.0.0/8 orlonger;
source-address-filter 127.0.0.0/8 orlonger;
}
then reject;
}
}
If the router is not configured with an export policy to block local source-active multicast advertisements, this is a finding.
M
5479