SV-254054r844195_rule
V-254054
SRG-NET-000364-RTR-000201
JUEX-RT-000820
CAT II
10
Configure the router to drop IPv6 packets with Routing Header of type 0, 1, or 3–255.
set firewall family inet6 filter <name> term 1 from next-header routing
set firewall family inet6 filter <name> term 1 then log
set firewall family inet6 filter <name> term 1 then syslog
set firewall family inet6 filter <name> term 1 then discard
<additional terms>
set firewall family inet6 filter <name> term default then log
set firewall family inet6 filter <name> term default then syslog
set firewall family inet6 filter <name> term default then discard
set interfaces <interface name> unit <number> family inet6 filter input <filter name>
set interfaces <interface name> unit <number> family inet6 address <IPv6 address>.<prefix>
This requirement is not applicable for the DODIN Backbone.
Review the router configuration to determine if it is configured to drop IPv6 packets containing a Routing Header of type 0, 1, or 3–255.
[edit firewall family inet6]
filter <name> {
term 1 {
from {
next-header routing;
}
then {
log;
syslog;
discard;
}
}
<additional terms>
term default {
then {
log;
syslog;
discard;
}
}
}
Note: Juniper routers do not support configuring option types for Routing extension headers. Therefore, all packets with the Routing extension header are dropped.
Verify the filter is applied to applicable interfaces.
[edit interfaces]
<interface name> {
unit <number> {
family inet6 {
filter {
input <filter name>;
}
address <IPv6 address>.<prefix>;
}
}
}
Note: Some Juniper devices support both monolithic filters and filter lists. Filter lists separate each term, or set of terms, into a separate filter that is applied sequentially to an interface. If using filter lists, the keywords "input" or "output" change to "input-list" or "output-list". Verify the final list item is a deny-all filter. The deny-all filter is created once per family and can be reused across multiple lists. For example:
input-list [ permit_mgt permit_routing_protocols default-deny ];
If the router is not configured to drop IPv6 packets containing a Routing Header of type 0, 1, or 3–255, this is a finding.
V-254054
False
JUEX-RT-000820
This requirement is not applicable for the DODIN Backbone.
Review the router configuration to determine if it is configured to drop IPv6 packets containing a Routing Header of type 0, 1, or 3–255.
[edit firewall family inet6]
filter <name> {
term 1 {
from {
next-header routing;
}
then {
log;
syslog;
discard;
}
}
<additional terms>
term default {
then {
log;
syslog;
discard;
}
}
}
Note: Juniper routers do not support configuring option types for Routing extension headers. Therefore, all packets with the Routing extension header are dropped.
Verify the filter is applied to applicable interfaces.
[edit interfaces]
<interface name> {
unit <number> {
family inet6 {
filter {
input <filter name>;
}
address <IPv6 address>.<prefix>;
}
}
}
Note: Some Juniper devices support both monolithic filters and filter lists. Filter lists separate each term, or set of terms, into a separate filter that is applied sequentially to an interface. If using filter lists, the keywords "input" or "output" change to "input-list" or "output-list". Verify the final list item is a deny-all filter. The deny-all filter is created once per family and can be reused across multiple lists. For example:
input-list [ permit_mgt permit_routing_protocols default-deny ];
If the router is not configured to drop IPv6 packets containing a Routing Header of type 0, 1, or 3–255, this is a finding.
M
5479