STIGQter STIGQter: STIG Summary: Arista MLS EOS 4.X Router Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Arista Multicast Source Discovery Protocol (MSDP) router must be configured to use its loopback address as the source address when originating MSDP traffic.

DISA Rule

SV-256056r991795_rule

Vulnerability Number

V-256056

Group Title

SRG-NET-000512-RTR-000011

Rule Version

ARST-RT-000770

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Ensure the Arista router originator-id is the source address loopback0 for originating traffic.

router(config)#router msdp
router (config-router-msdp)#originator-id local-interface loopback0
router (config-router-msdp)#exit

Check Contents

Review the Arista router configuration to verify a loopback address has been configured.

Verify a loopback interface is used as the source address for all MSDP packets generated by the router. Execute the command "sh run sec router msdp".

router#show running-config | section router msdp
router msdp
originator-id local-interface Loopback0

If the Arista router does not use its loopback address as the source address when originating MSDP traffic, this is a finding.

Vulnerability Number

V-256056

Documentable

False

Rule Version

ARST-RT-000770

Severity Override Guidance

Review the Arista router configuration to verify a loopback address has been configured.

Verify a loopback interface is used as the source address for all MSDP packets generated by the router. Execute the command "sh run sec router msdp".

router#show running-config | section router msdp
router msdp
originator-id local-interface Loopback0

If the Arista router does not use its loopback address as the source address when originating MSDP traffic, this is a finding.

Check Content Reference

M

Target Key

5513