STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia Provider Edge (PE) router must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all Customer Edge (CE)-facing interfaces.

DISA Rule

SV-283839r1203766_rule

Vulnerability Number

V-283839

Group Title

SRG-NET-000205-RTR-000008

Rule Version

NOKI-RT-000210

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable uRPF "loose" mode on all CE-facing interfaces, as shown in the example below:

- configure router interface "TO-CE" urpf-check mode loose

Check Contents

Review the router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces, as shown in the example below.

Verify "uRPF Chk" is set to "enabled" and "uRPF Chk Mode" is set to "loose":

- show router interface "TO-CE" detail | match "uRPF Chk"

uRPF Chk : enabled uRPF Chk Mode : loose

If "uRPF Chk" is not enabled and "uRPF Chk Mode" is not set to "loose" on all CE-facing interfaces, this is a finding.

Vulnerability Number

V-283839

Documentable

False

Rule Version

NOKI-RT-000210

Severity Override Guidance

Review the router configuration to determine if uRPF loose mode is enabled on all CE-facing interfaces, as shown in the example below.

Verify "uRPF Chk" is set to "enabled" and "uRPF Chk Mode" is set to "loose":

- show router interface "TO-CE" detail | match "uRPF Chk"

uRPF Chk : enabled uRPF Chk Mode : loose

If "uRPF Chk" is not enabled and "uRPF Chk Mode" is not set to "loose" on all CE-facing interfaces, this is a finding.

Check Content Reference

M

Target Key

5746