SV-283867r1203850_rule
V-283867
SRG-NET-000205-RTR-000016
NOKI-RT-000490
CAT II
10
Configure the router to drop all packets with IP options, as shown in the example below:
Create an IPv4 filter:
- configure filter ip-filter 10 create
- config>filter>ip-filter# entry 10 create
- config>filter>ip-filter>entry# match option-present true
- config>filter>ip-filter>entry# action drop
- config>filter>ip-filter>entry# exit all
Apply an IP-filter on the interface:
- configure router interface "TO-PE3" ingress filter ip 10
Review the router configuration to determine if it will block all packets with IP options.
Verify the IPv4 filter is applied on the interface using the command below:
- show router interface "TO-PE3" detail | match "Ingress Filter"
Egress Filter : none Ingress Filter : 10
If the router is not configured to drop all packets with IP options, this is a finding.
V-283867
False
NOKI-RT-000490
Review the router configuration to determine if it will block all packets with IP options.
Verify the IPv4 filter is applied on the interface using the command below:
- show router interface "TO-PE3" detail | match "Ingress Filter"
Egress Filter : none Ingress Filter : 10
If the router is not configured to drop all packets with IP options, this is a finding.
M
5746