STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia perimeter router must be configured to have Link Layer Discovery Protocols (LLDPs) disabled on all external interfaces and ensure LLDPs are not included in the system level.

DISA Rule

SV-283877r1203880_rule

Vulnerability Number

V-283877

Group Title

SRG-NET-000364-RTR-000111

Rule Version

NOKI-RT-000590

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

This requirement is not applicable for the DODIN Backbone.

Disable LLDP on the system level using the command below:

- configure system lldp shutdown

Disable LLDP on the port using the command below:

- configure port 1/1/c2/1
- config>port# ethernet lldp dest-mac nearest-bridge admin-status disabled
- config>port# exit all

Check Contents

This requirement is not applicable for the DODIN Backbone.

Review all router configurations to ensure LLDPs are not included in the global configuration or LLDPs are not included for each active external interface.

Verify LLDP "Admin Enabled" sis et to "False" in the system level using the command below:

- show system lldp | match "Admin Enabled"
Admin Enabled : False

Verify LLDP is in "Admin State" and set to "disabled" for all active external ports using the command below:

- show port 1/1/c2/1 ethernet lldp | match "Admin State"
Admin State : disabled Notifications : Disabled
Admin State : disabled Notifications : Disabled
Admin State : disabled Notifications : Disabled

If LLDPs are configured on the system and any external interface, this is a finding.

Vulnerability Number

V-283877

Documentable

False

Rule Version

NOKI-RT-000590

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Review all router configurations to ensure LLDPs are not included in the global configuration or LLDPs are not included for each active external interface.

Verify LLDP "Admin Enabled" sis et to "False" in the system level using the command below:

- show system lldp | match "Admin Enabled"
Admin Enabled : False

Verify LLDP is in "Admin State" and set to "disabled" for all active external ports using the command below:

- show port 1/1/c2/1 ethernet lldp | match "Admin State"
Admin State : disabled Notifications : Disabled
Admin State : disabled Notifications : Disabled
Admin State : disabled Notifications : Disabled

If LLDPs are configured on the system and any external interface, this is a finding.

Check Content Reference

M

Target Key

5746