STIGQter STIGQter: STIG Summary: RUCKUS ICX NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX device must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.

DISA Rule

SV-273829r1110847_rule

Vulnerability Number

V-273829

Group Title

SRG-APP-000435-NDM-000315

Rule Version

RCKS-NDM-000790

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DDoS protection:

SSH@ICX(config)# ip icmp attack-rate burst-normal 50 burst-max 100 lockup 300
SSH@ICX(config)# ip tcp burst-normal 30 burst-max 100 lockup 300

Note: burst-normal, burst-max, and lockup values may vary by site.

Check Contents

Check whether DDoS protection in place:

SSH@ICX# show running-config | include burst

ip icmp attack-rate burst-normal 50 burst-max 100 lockup 300
ip tcp burst-normal 30 burst-max 100 lockup 300

* burst-normal, burst-max, and lockup values may vary by site.

If the switch is not configured with DDoS protection this is a finding.

Vulnerability Number

V-273829

Documentable

False

Rule Version

RCKS-NDM-000790

Severity Override Guidance

Check whether DDoS protection in place:

SSH@ICX# show running-config | include burst

ip icmp attack-rate burst-normal 50 burst-max 100 lockup 300
ip tcp burst-normal 30 burst-max 100 lockup 300

* burst-normal, burst-max, and lockup values may vary by site.

If the switch is not configured with DDoS protection this is a finding.

Check Content Reference

M

Target Key

5695