STIGQter STIGQter: STIG Summary: RUCKUS ICX Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX PE router must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.

DISA Rule

SV-273612r1110923_rule

Vulnerability Number

V-273612

Group Title

SRG-NET-000205-RTR-000008

Rule Version

RCKS-RTR-000450

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable uRPF loose mode on all CE-facing interfaces.

1. Configure reverse-path-check globally.
ICX(config)#reverse-path-check
reverse-path-check setting changes requires a reload to take effect!
NOTE:
Configuring reverse-path-check reduces following system-max by half.
Following system-max will be reset to default. Please configure them after reload
Please adjust/remove max-route configuration in any vrf before reload.
Ip-route,ip6-route, ip-route-default-vrf, ip6-route-default-vrf, ip-route-vrf, ip6-route-vrf

2. Configure uRPF mode on CE interface(s).
ICX(config)#interface ethernet 1/1/1
ICX(config-if-e10000-1/1/1)#rpf-mode loose

Check Contents

Review the router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces.

1. Check that RPF is configured globally (requires reload when initially set).
reverse-path-check

2. Review the router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces.
Interface ethernet 1/1/1
rpf-mode loose

If uRPF loose mode is not enabled on all CE-facing interfaces, this is a finding.

Vulnerability Number

V-273612

Documentable

False

Rule Version

RCKS-RTR-000450

Severity Override Guidance

Review the router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces.

1. Check that RPF is configured globally (requires reload when initially set).
reverse-path-check

2. Review the router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces.
Interface ethernet 1/1/1
rpf-mode loose

If uRPF loose mode is not enabled on all CE-facing interfaces, this is a finding.

Check Content Reference

M

Target Key

5696