SV-254028r844260_rule
V-254028
SRG-NET-000343-RTR-000001
JUEX-RT-000560
CAT II
10
Implement authentication for all targeted LDP sessions using a FIPS-approved message authentication code algorithm.
set protocols ldp interface <interface 1 name>.<logical unit>
set protocols ldp interface <interface 2 name>.<logical unit>
set protocols ldp session <Session destination address> authentication-algorithm <aes-128-cmac-96|hmac-sha-1-96>
set protocols ldp session <Session destination address> authentication-key-chain <name>
Review the router configuration to determine if LDP messages are being authenticated for the targeted LDP sessions.
[edit protocols]
ldp {
interface <interface 1 name>.<logical unit>;
interface <interface 2 name>.<logical unit>;
session <Session destination address> {
authentication-algorithm <aes-128-cmac-96|hmac-sha-1-96>;
authentication-key-chain <name>;
}
}
If authentication is not being used for the LDP sessions using a FIPS-approved message authentication code algorithm, this is a finding.
V-254028
False
JUEX-RT-000560
Review the router configuration to determine if LDP messages are being authenticated for the targeted LDP sessions.
[edit protocols]
ldp {
interface <interface 1 name>.<logical unit>;
interface <interface 2 name>.<logical unit>;
session <Session destination address> {
authentication-algorithm <aes-128-cmac-96|hmac-sha-1-96>;
authentication-key-chain <name>;
}
}
If authentication is not being used for the LDP sessions using a FIPS-approved message authentication code algorithm, this is a finding.
M
5479