STIGQter STIGQter: STIG Summary: RUCKUS ICX Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX perimeter router must be configured to have Proxy ARP disabled on all external interfaces.

DISA Rule

SV-273645r1110946_rule

Vulnerability Number

V-273645

Group Title

SRG-NET-000364-RTR-000112

Rule Version

RCKS-RTR-000780

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This requirement is not applicable for the DODIN Backbone.

Disable IP Proxy ARP as shown in the example below:

ICX(config)# no ip proxy-arp

Check Contents

This requirement is not applicable for the DODIN Backbone.

Review the router configuration to determine if IP Proxy ARP has been enabled (see below):

ip proxy-arp

Note: By default, Proxy ARP is disabled globally.

If IP Proxy ARP is enabled, this is a finding.

Vulnerability Number

V-273645

Documentable

False

Rule Version

RCKS-RTR-000780

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Review the router configuration to determine if IP Proxy ARP has been enabled (see below):

ip proxy-arp

Note: By default, Proxy ARP is disabled globally.

If IP Proxy ARP is enabled, this is a finding.

Check Content Reference

M

Target Key

5696