STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia perimeter router must be configured to drop IPv6 undetermined transport packets.

DISA Rule

SV-283871r1203862_rule

Vulnerability Number

V-283871

Group Title

SRG-NET-000364-RTR-000200

Rule Version

NOKI-RT-000530

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the router to drop IPv6 undetermined transport/ first fragment packets, as shown in the example below:

Create an IPv6 filter:

- configure filter ipv6-filter 40 create
- config>filter>ipv6-filter# entry 10 create
- config>filter>ipv6-filter>entry$ match fragment first-only
- config>filter>ipv6-filter>entry$ action drop
- config>filter>ipv6-filter>entry$ exit all

Apply the IPv6 filter on the interface:

- configure router interface "TO-PE2" ingress filter ipv6 40

Check Contents

This requirement is not applicable for the DODIN Backbone.

Review the router configuration to determine if it is configured to drop IPv6 undetermined transport packets.

Verify the IPv6 filter is applied on the interface using the command below:

- show router interface "TO-PE2" detail | match "Ingr IPv6 Flt"
Egr IPv6 Flt : none Ingr IPv6 Flt : 40

If the router is not configured to drop IPv6 undetermined transport packets, this is a finding.

Vulnerability Number

V-283871

Documentable

False

Rule Version

NOKI-RT-000530

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Review the router configuration to determine if it is configured to drop IPv6 undetermined transport packets.

Verify the IPv6 filter is applied on the interface using the command below:

- show router interface "TO-PE2" detail | match "Ingr IPv6 Flt"
Egr IPv6 Flt : none Ingr IPv6 Flt : 40

If the router is not configured to drop IPv6 undetermined transport packets, this is a finding.

Check Content Reference

M

Target Key

5746