STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia Multiprotocol Label Switching (MPLS) router with Resource Reservation Protocol - Traffic Engineering (RSVP-TE) enabled must be configured with message pacing or refresh reduction to adjust the maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core routers.

DISA Rule

SV-283860r1203829_rule

Vulnerability Number

V-283860

Group Title

SRG-NET-000193-RTR-000001

Rule Version

NOKI-RT-000420

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Ensure all routers with RSVP-TE enabled have message pacing configured that will adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core routers.

Configure to enable message pacing for RSVP with a specified number of RSVP messages in the max-burst command, as shown in the example below:

- configure router rsvp msg-pacing max-burst 200
- configure router rsvp msg-pacing period 200

Check Contents

Review the Nokia router configuration to verify the router has been configured to prevent a burst of RSVP traffic engineering signaling messages from overflowing the input queue of any neighbor core router.

Use the command below and verify "Message Pacing" is enabled:

- show router rsvp status | match "Message Pacing" post-lines 1
Message Pacing : Enabled Pacing Period : 200 msec
Max Packet Burst : 200 msgs Refresh Bypass : Disabled

If the router with RSVP-TE enabled does not have message pacing configured based on the link speed and input queue size of adjacent core routers, this is a finding.

Vulnerability Number

V-283860

Documentable

False

Rule Version

NOKI-RT-000420

Severity Override Guidance

Review the Nokia router configuration to verify the router has been configured to prevent a burst of RSVP traffic engineering signaling messages from overflowing the input queue of any neighbor core router.

Use the command below and verify "Message Pacing" is enabled:

- show router rsvp status | match "Message Pacing" post-lines 1
Message Pacing : Enabled Pacing Period : 200 msec
Max Packet Burst : 200 msgs Refresh Bypass : Disabled

If the router with RSVP-TE enabled does not have message pacing configured based on the link speed and input queue size of adjacent core routers, this is a finding.

Check Content Reference

M

Target Key

5746