STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia Provider Edge (PE) router providing Multiprotocol Label Switching (MPLS) Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.

DISA Rule

SV-283824r1203721_rule

Vulnerability Number

V-283824

Group Title

SRG-NET-000512-RTR-000008

Rule Version

NOKI-RT-000060

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Assign globally unique VC IDs for each virtual circuit and configure the attachment circuits with the appropriate VC ID.

Configure the same VC ID on both ends of the VC, as shown in the example below:

- configure service epipe 10 customer 1 create
- config>service>epipe# spoke-sdp 40:10 create
- config>service>epipe>spoke-sdp# exit
- config>service>epipe# sap 1/1/c3/1 create
- config>service>epipe>sap# exit all

Check Contents

Review the ingress and egress PE router configuration for each virtual circuit that has been provisioned and verify the correct and unique VCID has been configured for the appropriate attachment circuit.

Use the following command to verify "SvcId" and "VCID" fields and confirm the correct VC ID has been configured for the correct service, as shown in the example below:

- show router ldp bindings services | match "VCId" post-lines 5

Type VCId SDPId LMTU
Peer SvcId IngLbl RMTU
EgrLbl
-------------------------------------------------------------------------------
E-Eth 10 40 1500
4.4.4.4:0 10 524282U 1500

Note: Ethernet over MPLS in VLAN mode transports Ethernet traffic from a source 802.1Q VLAN to a destination 802.1Q VLAN over a core MPLS network. The VC ID must be unique and the same on each end as it is used to connect the endpoints of the VC.

If the correct VC ID has not been configured on both routers, this is a finding.

Vulnerability Number

V-283824

Documentable

False

Rule Version

NOKI-RT-000060

Severity Override Guidance

Review the ingress and egress PE router configuration for each virtual circuit that has been provisioned and verify the correct and unique VCID has been configured for the appropriate attachment circuit.

Use the following command to verify "SvcId" and "VCID" fields and confirm the correct VC ID has been configured for the correct service, as shown in the example below:

- show router ldp bindings services | match "VCId" post-lines 5

Type VCId SDPId LMTU
Peer SvcId IngLbl RMTU
EgrLbl
-------------------------------------------------------------------------------
E-Eth 10 40 1500
4.4.4.4:0 10 524282U 1500

Note: Ethernet over MPLS in VLAN mode transports Ethernet traffic from a source 802.1Q VLAN to a destination 802.1Q VLAN over a core MPLS network. The VC ID must be unique and the same on each end as it is used to connect the endpoints of the VC.

If the correct VC ID has not been configured on both routers, this is a finding.

Check Content Reference

M

Target Key

5746