STIGQter STIGQter: STIG Summary: RUCKUS ICX Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.

DISA Rule

SV-273609r1111034_rule

Vulnerability Number

V-273609

Group Title

SRG-NET-000205-RTR-000005

Rule Version

RCKS-RTR-000420

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This requirement is not applicable for the DODIN Backbone.

Configure ACLs to internal interface(s):
ICX(config)# interface ethernet x/x/x
ICX(config-if-e1000-x/x/x)# port-name internal-interface
ICX(config-if-e1000-x/x/x)#ip access-group INT-ACL in logging enable

Check Contents

This requirement is not applicable for the DODIN Backbone.

Verify ACLs are applied to desired internal interfaces on the inbound direction:
interface ethernet x/x/x
port-name internal-interface
ip address x.11.1.2/31
ip access-group INT-ACL in logging enable
!

If the perimeter router is not configured to filter traffic leaving the network on the inbound direction of internal interface(s), this is a finding.

Vulnerability Number

V-273609

Documentable

False

Rule Version

RCKS-RTR-000420

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Verify ACLs are applied to desired internal interfaces on the inbound direction:
interface ethernet x/x/x
port-name internal-interface
ip address x.11.1.2/31
ip access-group INT-ACL in logging enable
!

If the perimeter router is not configured to filter traffic leaving the network on the inbound direction of internal interface(s), this is a finding.

Check Content Reference

M

Target Key

5696