STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia perimeter router must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DOD Instruction (DODI) 8551.1.

DISA Rule

SV-283823r1203718_rule

Vulnerability Number

V-283823

Group Title

SRG-NET-000205-RTR-000003

Rule Version

NOKI-RT-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This requirement is not applicable for the DODIN Backbone.

Configure the router to use ingress ACLs to restrict traffic in accordance with the guidelines in DODI 8551.1 for all services and protocols required for operational commitments, as shown in the example below:

IPv4 filter:

- configure filter ip-filter 10 create
- config>filter>ip-filter# entry 10 create
- config>filter>ip-filter>entry# match src-ip 172.200.200.2/32
- config>filter>ip-filter>entry# action drop
- config>filter>ip-filter>entry# exit all

IPv6 filter:

- configure filter ipv6-filter 20 create
- config>filter>ipv6-filter# entry 10 create
- config>filter>ipv6-filter>entry# match src-ip 2001:acad:1234:200::2/128
- config>filter>ipv6-filter>entry# action drop
- config>filter>ipv6-filter>entry# exit all

Apply the filter to the interface:

- configure router interface "TO-PE2" ingress filter ip 10
- configure router interface "TO-PE2" ingress filter ipv6 20

Check Contents

This requirement is not applicable for the DODIN Backbone.

Review the router configuration to verify the ingress filter is in accordance with DODI 8551.

Verify all interfaces have ingress filters for IPv4 and IPv6 assigned, as shown in the example below:

- show router interface "TO-PE2" detail | match "Ingress Filter"
Egress Filter : none Ingress Filter : 10

- show router interface "TO-PE2" detail | match "Ingr IPv6 Flt"
Egr IPv6 Flt : none Ingr IPv6 Flt : 20

If the router does not filter traffic in accordance with the guidelines contained in DODI 8551, this is a finding.

Vulnerability Number

V-283823

Documentable

False

Rule Version

NOKI-RT-000050

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Review the router configuration to verify the ingress filter is in accordance with DODI 8551.

Verify all interfaces have ingress filters for IPv4 and IPv6 assigned, as shown in the example below:

- show router interface "TO-PE2" detail | match "Ingress Filter"
Egress Filter : none Ingress Filter : 10

- show router interface "TO-PE2" detail | match "Ingr IPv6 Flt"
Egr IPv6 Flt : none Ingr IPv6 Flt : 20

If the router does not filter traffic in accordance with the guidelines contained in DODI 8551, this is a finding.

Check Content Reference

M

Target Key

5746