STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia router must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.

DISA Rule

SV-283783r1223372_rule

Vulnerability Number

V-283783

Group Title

SRG-APP-000435-NDM-000315

Rule Version

NOKI-ND-000760

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nokia router to protect against or limit the effects of all known types of DoS attacks by employing organization-defined security safeguards.

Configure Distributed CPU Protection to rate limit various core/peering protocols, Link, ESM, interface protocols, and any other unspecified control traffic, as shown in the example below:

- configure system security dist-cpu-protection policy <policy name> create
- static-policer <name> create
- rate packets <ppi| ma> within <seconds>
OR
- rate kbps <kbps | max> bytes mbs <size>
- exceed-action discard
- back
- protocol <protocol name or all-unspecified> create

Apply the policy to each interface:

- configure router inter <interface name> dist-cpu-protection <policy name>

Check Contents

Determine if the Nokia router protects against or limits the effects of all known types of DoS attacks by employing organization-defined security safeguards.

Verify Distributed CPU Protection is configured for each interface, as shown in the example below:

- show router interface detail | match OperDCpuProtPlcy
OperDCpuProtPlcy : test
OperDCpuProtPlcy : ssh

If the Nokia router does not protect against or limit the effects of all known types of DoS attacks by employing organization-defined security safeguards, this is a finding.

Vulnerability Number

V-283783

Documentable

False

Rule Version

NOKI-ND-000760

Severity Override Guidance

Determine if the Nokia router protects against or limits the effects of all known types of DoS attacks by employing organization-defined security safeguards.

Verify Distributed CPU Protection is configured for each interface, as shown in the example below:

- show router interface detail | match OperDCpuProtPlcy
OperDCpuProtPlcy : test
OperDCpuProtPlcy : ssh

If the Nokia router does not protect against or limit the effects of all known types of DoS attacks by employing organization-defined security safeguards, this is a finding.

Check Content Reference

M

Target Key

5744