STIGQter STIGQter: STIG Summary: RUCKUS ICX Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.

DISA Rule

SV-273586r1111032_rule

Vulnerability Number

V-273586

Group Title

SRG-NET-000019-RTR-000009

Rule Version

RCKS-RTR-000180

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

This requirement is not applicable for the DODIN Backbone.

Delete the BGP peer statement to the alternate gateway service provider:
ICX(config)# router bgp
ICX(config-bgp-router)# no neighbor x.x.x.x remote-as yyyy

If necessary, configure a default route to the alternate gateway service provider:
ICX(config)# ip route 0.0.0.0/0 x.x.x.x

Check Contents

This requirement is not applicable for the DODIN Backbone.

Determine the IP address of the alternate gateway service provider and confirm that the ICX is not configured with that address as a BGP peer.

If the ICX is configured with the alternate gateway service provider IP address as a BGP peer, this is a finding.

Vulnerability Number

V-273586

Documentable

False

Rule Version

RCKS-RTR-000180

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Determine the IP address of the alternate gateway service provider and confirm that the ICX is not configured with that address as a BGP peer.

If the ICX is configured with the alternate gateway service provider IP address as a BGP peer, this is a finding.

Check Content Reference

M

Target Key

5696