SV-283886r1203907_rule
V-283886
SRG-NET-000019-RTR-000012
NOKI-RT-000700
CAT II
10
This requirement is not applicable for the DODIN Backbone.
Configure the IGP instance used for the managed network to prohibit redistribution of routes into the IGP instance used for the management network, and vice versa.
Configure VPRN services for MGMT using the commands below:
- configure service vprn 30 customer 1 create
- config>service>vprn# autonomous-system 65100
- config>service>vprn# interface "TO-MGMT" create
- config>service>vprn>if# address 192.168.1.1/30
- config>service>vprn>if# sap 1/1/c5/1 create
- config>service>vprn>if>sap# exit
- config>service>vprn>if# exit
- config>service>vprn# bgp-ipvpn
- config>service>vprn>bgp-ipvpn# mpls
- config>service>vprn>bgp-ipvpn>mpls# auto-bind-tunnel resolution any
- config>service>vprn>bgp-ipvpn>mpls# route-distinguisher 3.3.3.3:30
- config>service>vprn>bgp-ipvpn>mpls# vrf-target target:65100:300
- config>service>vprn>bgp-ipvpn>mpls# no shutdown
- config>service>vprn>bgp-ipvpn>mpls# exit
- config>service>vprn>bgp-ipvpn# exit
- config>service>vprn# ospf
- config>service>vprn>ospf# area 0.0.0.0
- config>service>vprn>ospf>area# interface "TO-MGMT"
- config>service>vprn>ospf>area>if# no shutdown
- config>service>vprn>ospf>area>if# exit
- config>service>vprn>ospf>area# exit
- config>service>vprn>ospf# no shutdown
- config>service>vprn>ospf# exit
- config>service>vprn# no shutdown
- config>service>vprn# exit all
Configure VPRN service for PROD using the commands below:
- configure service vprn 40 customer 1 create
- config>service>vprn$ router-id 3.3.3.3
- config>service>vprn$ autonomous-system 65100
- config>service>vprn$ interface TO-PROD create
- config>service>vprn>if$ address 192.168.2.1/30
- config>service>vprn>if$ sap 1/1/c6/1 create
- config>service>vprn>if>sap$ exit
- config>service>vprn>if$ exit
- config>service>vprn$ bgp-ipvpn
- config>service>vprn>bgp-ipvpn$ mpls
- config>service>vprn>bgp-ipvpn>mpls$ auto-bind-tunnel resolution any
- config>service>vprn>bgp-ipvpn>mpls$ route-distinguisher 3.3.3.3:40
- config>service>vprn>bgp-ipvpn>mpls$ vrf-target target:65100:40
- config>service>vprn>bgp-ipvpn>mpls$ no shutdown
- config>service>vprn>bgp-ipvpn>mpls$ exit
- config>service>vprn>bgp-ipvpn$ exit
- config>service>vprn$ ospf
- config>service>vprn>ospf$ area 0
- config>service>vprn>ospf>area$ interface "TO-PROD"
- config>service>vprn>ospf>area>if$ no shutdown
- config>service>vprn>ospf>area>if$ exit
- config>service>vprn>ospf>area$ exit
- config>service>vprn>ospf$ no shutdown
- config>service>vprn>ospf$ exit
- config>service>vprn# no shutdown
- config>service>vprn# exit all
This requirement is not applicable for the DODIN Backbone.
Verify the IGP instance used for the managed network does not redistribute routes into the Interior Gateway Protocol instance used for the management network and vice versa.
Verify Virtual Private Routed Network (VPRN) services for MGMT and PROD using the command below:
- show service id 30 base
Service Basic Information
Service Id : 30 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 30
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 02:36:25
Last Mgmt Change : 12/18/2025 02:36:25
Admin State : Up Oper State : Up
Router Oper State : Up
Route Dist. : 3.3.3.3:30 VPRN Type : regular
Oper Route Dist : 3.3.3.3:30
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled
Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled
Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:300
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled
SAP Count : 1 SDP Bind Count : 0
-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c5/1 null 1514 1514 Up Up
- show service id 40 base
Service Basic Information
Service Id : 40 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 40
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 16:09:25
Last Mgmt Change : 12/18/2025 16:09:25
Admin State : Up Oper State : Up
Router Oper State : Up
Route Dist. : 3.3.3.3:40 VPRN Type : regular
Oper Route Dist : 3.3.3.3:40
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled
Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled
Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:40
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled
SAP Count : 1 SDP Bind Count : 0
-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c6/1 null 1514 1514 Up Up
If the IGP instance used for the managed network redistributes routes into the IGP instance used for the management network, or vice versa, this is a finding.
V-283886
False
NOKI-RT-000700
This requirement is not applicable for the DODIN Backbone.
Verify the IGP instance used for the managed network does not redistribute routes into the Interior Gateway Protocol instance used for the management network and vice versa.
Verify Virtual Private Routed Network (VPRN) services for MGMT and PROD using the command below:
- show service id 30 base
Service Basic Information
Service Id : 30 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 30
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 02:36:25
Last Mgmt Change : 12/18/2025 02:36:25
Admin State : Up Oper State : Up
Router Oper State : Up
Route Dist. : 3.3.3.3:30 VPRN Type : regular
Oper Route Dist : 3.3.3.3:30
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled
Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled
Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:300
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled
SAP Count : 1 SDP Bind Count : 0
-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c5/1 null 1514 1514 Up Up
- show service id 40 base
Service Basic Information
Service Id : 40 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 40
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 16:09:25
Last Mgmt Change : 12/18/2025 16:09:25
Admin State : Up Oper State : Up
Router Oper State : Up
Route Dist. : 3.3.3.3:40 VPRN Type : regular
Oper Route Dist : 3.3.3.3:40
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled
Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled
Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:40
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled
SAP Count : 1 SDP Bind Count : 0
-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c6/1 null 1514 1514 Up Up
If the IGP instance used for the managed network redistributes routes into the IGP instance used for the management network, or vice versa, this is a finding.
M
5746