STIGQter STIGQter: STIG Summary: RUCKUS ICX Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX router must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.

DISA Rule

SV-273628r1111067_rule

Vulnerability Number

V-273628

Group Title

SRG-NET-000362-RTR-000110

Rule Version

RCKS-RTR-000610

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DDoS protection.

ICX(config)#ip icmp attack-rate burst-normal 500 burst-max 1000 lockup 300
ICX(config)#ip tcp burst-normal 30 burst-max 100 lockup 300

Check Contents

Review configuration to determine whether distributed denial-of-service (DDoS) attack prevention is configured (values may vary):

ICX#show running-config | include burst
ip icmp attack-rate burst-normal 500 burst-max 1000 lockup 300
ip tcp burst-normal 30 burst-max 100 lockup 300

If DDoS protection is not configured, this is a finding.

Vulnerability Number

V-273628

Documentable

False

Rule Version

RCKS-RTR-000610

Severity Override Guidance

Review configuration to determine whether distributed denial-of-service (DDoS) attack prevention is configured (values may vary):

ICX#show running-config | include burst
ip icmp attack-rate burst-normal 500 burst-max 1000 lockup 300
ip tcp burst-normal 30 burst-max 100 lockup 300

If DDoS protection is not configured, this is a finding.

Check Content Reference

M

Target Key

5696