SV-273591r1110892_rule
V-273591
SRG-NET-000019-RTR-000014
RCKS-RTR-000230
CAT III
10
Note: Standard ACLs can only be applied to specific RPs. Extended ACLs must be used when applying to any RP.
Configure filter for PIM Join messages and apply to PIM:
ICX(config)#ip access stand FILTER_PIM_JOINS
ICX(config-std-ipacl-FILTER_PIM_JOINS)#deny 239.8.0.0/16
ICX(config-std-ipacl-FILTER_PIM_JOINS)#exit
ICX(config)#router pim
ICX(config-pim-router)#jp-policy 10.1.1.1 FILTER_PIM_JOINS
Check PIM sparse Join/Prune policy configuration for required filters:
ICX# show ip pim jp
Vrf Instance : default-vrf
---------------------------
(RP,G) JP policy
---------
(RP,G) JP policy count: 1
RP-Address ACL Name (RP,G) Join Drops (RP,G) Prune Drops
10.1.1.1 FILTER_PIM_JOINS 0 0
(*,G) and (S,G) JP policy
---------
ACL Name (*,G) Join Drops (*,G) Prune Drops (S,G) Join Drops (S,G) Prune Drops
EXT_FILTER_PIM_JOINS 0 0 0 0
If the RP is not configured to filter PIM register messages, this is a finding.
V-273591
False
RCKS-RTR-000230
Check PIM sparse Join/Prune policy configuration for required filters:
ICX# show ip pim jp
Vrf Instance : default-vrf
---------------------------
(RP,G) JP policy
---------
(RP,G) JP policy count: 1
RP-Address ACL Name (RP,G) Join Drops (RP,G) Prune Drops
10.1.1.1 FILTER_PIM_JOINS 0 0
(*,G) and (S,G) JP policy
---------
ACL Name (*,G) Join Drops (*,G) Prune Drops (S,G) Join Drops (S,G) Prune Drops
EXT_FILTER_PIM_JOINS 0 0 0 0
If the RP is not configured to filter PIM register messages, this is a finding.
M
5696