STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia Multiprotocol Label Switching (MPLS) router must be configured to have time-to-live (TTL) propagation disabled.

DISA Rule

SV-283854r1203811_rule

Vulnerability Number

V-283854

Group Title

SRG-NET-000512-RTR-000004

Rule Version

NOKI-RT-000360

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable the propagation of the TTL for locally generated packets and transit packets for all LSP shortcuts originating on this ingress LER, as shown in the configuration below:

- configure router mpls no shortcut-local-ttl-propagate
- configure router mpls no shortcut-transit-ttl-propagate

Check Contents

Review the router configuration to verify TTL propagation is disabled.

Use the command below to verify "Local TTL Prop" and/or "Transit TTL Prop" has been disabled:

- show router mpls status | match "TTL Prop"
Local TTL Prop : Disabled Transit TTL Prop : Disabled

If the router is not configured to disable TTL propagation, this is a finding.

Vulnerability Number

V-283854

Documentable

False

Rule Version

NOKI-RT-000360

Severity Override Guidance

Review the router configuration to verify TTL propagation is disabled.

Use the command below to verify "Local TTL Prop" and/or "Transit TTL Prop" has been disabled:

- show router mpls status | match "TTL Prop"
Local TTL Prop : Disabled Transit TTL Prop : Disabled

If the router is not configured to disable TTL propagation, this is a finding.

Check Content Reference

M

Target Key

5746