STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia Provider Edge (PE) router providing virtual private local area network services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.

DISA Rule

SV-283826r1203727_rule

Vulnerability Number

V-283826

Group Title

SRG-NET-000512-RTR-000009

Rule Version

NOKI-RT-000080

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Assign globally unique Service IDs for each customer VLAN using VPLS for carrier Ethernet services between multiple sites, and configure the attachment circuits to the appropriate VFI:

- configure service vpls 20 vpn 20 customer 1 create
- config>service>vpls# mesh-sdp 40:20 create
- config>service>vpls>mesh-sdp# exit
- config>service>vpls# sap 1/1/c5/1:100 create
- config>service>vpls>sap# exit
- config>service>vpls# no shutdown
- config>service>vpls# exit all

Check Contents

Review the implementation plan and the Service IDs assigned to customer VLANs for the VPLS deployment.

Review the PE router configuration to verify customer attachment circuits (i.e., VLANs) are associated to the appropriate VFI. In the example below, the attached circuit at port 1/1/c5/1 is associated to Service ID 20.

Use the following command:

- show service id 20 base

Service Basic Information
Service Id : 20 Vpn Id : 20
Service Type : VPLS

—--- snip —---
-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c5/1:100 q-tag 1518 1518 Up Up
sdp:30:20 M(3.3.3.3) Mesh 0 9190 Up Up

If the attachment circuits have not been bound to VFI configured with the assigned Service ID for each VLAN, this is a finding.

Vulnerability Number

V-283826

Documentable

False

Rule Version

NOKI-RT-000080

Severity Override Guidance

Review the implementation plan and the Service IDs assigned to customer VLANs for the VPLS deployment.

Review the PE router configuration to verify customer attachment circuits (i.e., VLANs) are associated to the appropriate VFI. In the example below, the attached circuit at port 1/1/c5/1 is associated to Service ID 20.

Use the following command:

- show service id 20 base

Service Basic Information
Service Id : 20 Vpn Id : 20
Service Type : VPLS

—--- snip —---
-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c5/1:100 q-tag 1518 1518 Up Up
sdp:30:20 M(3.3.3.3) Mesh 0 9190 Up Up

If the attachment circuits have not been bound to VFI configured with the assigned Service ID for each VLAN, this is a finding.

Check Content Reference

M

Target Key

5746