STIGQter STIGQter: STIG Summary: Juniper EX Series Switches Router Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Juniper multicast edge router must be configured to establish boundaries for administratively scoped multicast traffic.

DISA Rule

SV-253987r843994_rule

Vulnerability Number

V-253987

Group Title

SRG-NET-000019-RTR-000005

Rule Version

JUEX-RT-000150

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the policy to deny packets with multicast administratively scoped destination addresses.
set routing-options multicast scope <IPv4 scope name> prefix 239.0.0.0/8;
set routing-options multicast scope <IPv6 scope name> prefix ff08::/16;

-or-

set policy-options policy-statement <policy name> term 1 from route-filter 239.0.0.0/8 orlonger
set policy-options policy-statement <policy name> term 1 from route-filter ff08::/16 orlonger

Apply the multicast boundary at the appropriate interfaces.
set routing-options multicast scope <IPv4 scope name> interface [ <external interface 1> <external interface 2> ]
set routing-options multicast scope <IPv6 scope name> interface [ <external interface 1> <external interface 2> ]

-or-

set routing-options multicast scope-policy <policy name>

Check Contents

Review the router configuration and verify that admin-scope multicast traffic is blocked at the external edge.

Verify either a scope is defined for specific interfaces or a scope policy is applied.
[edit routing-options multicast]
scope <name IPv4> {
prefix 239.0.0.0/8;
interface [ <external interface 1> <external interface 2> ];
}
scope <name IPv6> {
prefix ff08::/16;
interface [ <external interface 1> <external interface 2> ];
}

-or-

[edit policy-options]
policy-statement <name> {
term 1 {
from {
route-filter 239.0.0.0/8 orlonger;
route-filter ff08::/16 orlonger;
}
then reject;
}
}
[edit routing-options multicast]
scope-policy <policy name>

If the router is not configured to establish boundaries for administratively scoped multicast traffic, this is a finding.

Vulnerability Number

V-253987

Documentable

False

Rule Version

JUEX-RT-000150

Severity Override Guidance

Review the router configuration and verify that admin-scope multicast traffic is blocked at the external edge.

Verify either a scope is defined for specific interfaces or a scope policy is applied.
[edit routing-options multicast]
scope <name IPv4> {
prefix 239.0.0.0/8;
interface [ <external interface 1> <external interface 2> ];
}
scope <name IPv6> {
prefix ff08::/16;
interface [ <external interface 1> <external interface 2> ];
}

-or-

[edit policy-options]
policy-statement <name> {
term 1 {
from {
route-filter 239.0.0.0/8 orlonger;
route-filter ff08::/16 orlonger;
}
then reject;
}
}
[edit routing-options multicast]
scope-policy <policy name>

If the router is not configured to establish boundaries for administratively scoped multicast traffic, this is a finding.

Check Content Reference

M

Target Key

5479