STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia Provider Edge (PE) router providing Multiprotocol Label Switching (MPLS) layer 2 virtual private network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit information using a Federal Information Processing Standards (FIPS)-approved message authentication code algorithm.

DISA Rule

SV-283878r1203883_rule

Vulnerability Number

V-283878

Group Title

SRG-NET-000343-RTR-000001

Rule Version

NOKI-RT-000600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure all targeted LDP sessions using a FIPS-approved message authentication code algorithm, as shown in the example below:

- configure router ldp tcp-session-parameters authentication-key pass123

Check Contents

Review the router configuration to determine if LDP messages are being authenticated for the targeted LDP sessions.

Verify "Authentication Key" is enabled using the command below:

- show router ldp tcp-session-parameters | match "Authentication Key"

Authentication Key : Enabled

If authentication is not being used for the LDP sessions using a FIPS-approved message authentication code algorithm, this is a finding.

Vulnerability Number

V-283878

Documentable

False

Rule Version

NOKI-RT-000600

Severity Override Guidance

Review the router configuration to determine if LDP messages are being authenticated for the targeted LDP sessions.

Verify "Authentication Key" is enabled using the command below:

- show router ldp tcp-session-parameters | match "Authentication Key"

Authentication Key : Enabled

If authentication is not being used for the LDP sessions using a FIPS-approved message authentication code algorithm, this is a finding.

Check Content Reference

M

Target Key

5746