STIGQter STIGQter: STIG Summary: Arista MLS EOS 4.X Router Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Arista router must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.

DISA Rule

SV-256022r882408_rule

Vulnerability Number

V-256022

Group Title

SRG-NET-000205-RTR-000008

Rule Version

ARST-RT-000410

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable uRPF loose mode on all CE-facing interfaces.

Configure uRPF loose mode on all CE-facing interfaces.

router(config)#interface Ethernet 3/17/1
router(config-if-Et3/17/1)#ip verify unicast source reachable-via any
router(config-if-Et3/17/1)#end

Check Contents

Review the Arista router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces.

To verify the interface configuration uRPF loose mode is enabled on all CE-facing interfaces, execute the command "sh run int Eth YY".

interface Ethernet 3/17/1
ip address 10.10.22.1/30
ip verify unicast source reachable-via any

If uRPF loose mode is not enabled on all CE-facing interfaces, this is a finding.

Vulnerability Number

V-256022

Documentable

False

Rule Version

ARST-RT-000410

Severity Override Guidance

Review the Arista router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces.

To verify the interface configuration uRPF loose mode is enabled on all CE-facing interfaces, execute the command "sh run int Eth YY".

interface Ethernet 3/17/1
ip address 10.10.22.1/30
ip verify unicast source reachable-via any

If uRPF loose mode is not enabled on all CE-facing interfaces, this is a finding.

Check Content Reference

M

Target Key

5513