STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Router Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia out-of-band management (OOBM) gateway router must be configured to not redistribute routes between the management network routing domain and the managed network routing domain.

DISA Rule

SV-283886r1203907_rule

Vulnerability Number

V-283886

Group Title

SRG-NET-000019-RTR-000012

Rule Version

NOKI-RT-000700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This requirement is not applicable for the DODIN Backbone.

Configure the IGP instance used for the managed network to prohibit redistribution of routes into the IGP instance used for the management network, and vice versa.

Configure VPRN services for MGMT using the commands below:

- configure service vprn 30 customer 1 create
- config>service>vprn# autonomous-system 65100
- config>service>vprn# interface "TO-MGMT" create
- config>service>vprn>if# address 192.168.1.1/30
- config>service>vprn>if# sap 1/1/c5/1 create
- config>service>vprn>if>sap# exit
- config>service>vprn>if# exit
- config>service>vprn# bgp-ipvpn
- config>service>vprn>bgp-ipvpn# mpls
- config>service>vprn>bgp-ipvpn>mpls# auto-bind-tunnel resolution any
- config>service>vprn>bgp-ipvpn>mpls# route-distinguisher 3.3.3.3:30
- config>service>vprn>bgp-ipvpn>mpls# vrf-target target:65100:300
- config>service>vprn>bgp-ipvpn>mpls# no shutdown
- config>service>vprn>bgp-ipvpn>mpls# exit
- config>service>vprn>bgp-ipvpn# exit
- config>service>vprn# ospf
- config>service>vprn>ospf# area 0.0.0.0
- config>service>vprn>ospf>area# interface "TO-MGMT"
- config>service>vprn>ospf>area>if# no shutdown
- config>service>vprn>ospf>area>if# exit
- config>service>vprn>ospf>area# exit
- config>service>vprn>ospf# no shutdown
- config>service>vprn>ospf# exit
- config>service>vprn# no shutdown
- config>service>vprn# exit all

Configure VPRN service for PROD using the commands below:

- configure service vprn 40 customer 1 create
- config>service>vprn$ router-id 3.3.3.3
- config>service>vprn$ autonomous-system 65100
- config>service>vprn$ interface TO-PROD create
- config>service>vprn>if$ address 192.168.2.1/30
- config>service>vprn>if$ sap 1/1/c6/1 create
- config>service>vprn>if>sap$ exit
- config>service>vprn>if$ exit
- config>service>vprn$ bgp-ipvpn
- config>service>vprn>bgp-ipvpn$ mpls
- config>service>vprn>bgp-ipvpn>mpls$ auto-bind-tunnel resolution any
- config>service>vprn>bgp-ipvpn>mpls$ route-distinguisher 3.3.3.3:40
- config>service>vprn>bgp-ipvpn>mpls$ vrf-target target:65100:40
- config>service>vprn>bgp-ipvpn>mpls$ no shutdown
- config>service>vprn>bgp-ipvpn>mpls$ exit
- config>service>vprn>bgp-ipvpn$ exit
- config>service>vprn$ ospf
- config>service>vprn>ospf$ area 0
- config>service>vprn>ospf>area$ interface "TO-PROD"
- config>service>vprn>ospf>area>if$ no shutdown
- config>service>vprn>ospf>area>if$ exit
- config>service>vprn>ospf>area$ exit
- config>service>vprn>ospf$ no shutdown
- config>service>vprn>ospf$ exit
- config>service>vprn# no shutdown
- config>service>vprn# exit all

Check Contents

This requirement is not applicable for the DODIN Backbone.

Verify the IGP instance used for the managed network does not redistribute routes into the Interior Gateway Protocol instance used for the management network and vice versa.

Verify Virtual Private Routed Network (VPRN) services for MGMT and PROD using the command below:

- show service id 30 base

Service Basic Information

Service Id : 30 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 30
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 02:36:25
Last Mgmt Change : 12/18/2025 02:36:25
Admin State : Up Oper State : Up

Router Oper State : Up
Route Dist. : 3.3.3.3:30 VPRN Type : regular
Oper Route Dist : 3.3.3.3:30
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled

Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled

Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:300
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled

SAP Count : 1 SDP Bind Count : 0

-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c5/1 null 1514 1514 Up Up

- show service id 40 base

Service Basic Information

Service Id : 40 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 40
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 16:09:25
Last Mgmt Change : 12/18/2025 16:09:25
Admin State : Up Oper State : Up

Router Oper State : Up
Route Dist. : 3.3.3.3:40 VPRN Type : regular
Oper Route Dist : 3.3.3.3:40
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled

Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled

Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:40
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled

SAP Count : 1 SDP Bind Count : 0

-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c6/1 null 1514 1514 Up Up

If the IGP instance used for the managed network redistributes routes into the IGP instance used for the management network, or vice versa, this is a finding.

Vulnerability Number

V-283886

Documentable

False

Rule Version

NOKI-RT-000700

Severity Override Guidance

This requirement is not applicable for the DODIN Backbone.

Verify the IGP instance used for the managed network does not redistribute routes into the Interior Gateway Protocol instance used for the management network and vice versa.

Verify Virtual Private Routed Network (VPRN) services for MGMT and PROD using the command below:

- show service id 30 base

Service Basic Information

Service Id : 30 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 30
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 02:36:25
Last Mgmt Change : 12/18/2025 02:36:25
Admin State : Up Oper State : Up

Router Oper State : Up
Route Dist. : 3.3.3.3:30 VPRN Type : regular
Oper Route Dist : 3.3.3.3:30
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled

Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled

Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:300
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled

SAP Count : 1 SDP Bind Count : 0

-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c5/1 null 1514 1514 Up Up

- show service id 40 base

Service Basic Information

Service Id : 40 Vpn Id : 0
Service Type : VPRN
MACSec enabled : no
Name : 40
Description : (Not Specified)
Customer Id : 1 Creation Origin : manual
Last Status Change: 12/18/2025 16:09:25
Last Mgmt Change : 12/18/2025 16:09:25
Admin State : Up Oper State : Up

Router Oper State : Up
Route Dist. : 3.3.3.3:40 VPRN Type : regular
Oper Route Dist : 3.3.3.3:40
Oper RD Type : configured
AS Number : 65100 Router Id : 3.3.3.3
ECMP : Enabled ECMP Max Routes : 1
Max IPv4 Routes : No Limit
Local Rt Domain-Id: None D-Path Lng Ignore : Disabled

Auto Bind Tunnel
Allow Flex-Alg-Fb : Disabled
Resolution : any
Weighted ECMP : Disabled ECMP Max Routes : 1
Strict Tnl Tag : Disabled

Max IPv6 Routes : No Limit
Ignore NH Metric : Disabled
Hash Label : Disabled
Entropy Label : Disabled
Vrf Target : target:65100:40
Vrf Import : None
Vrf Export : None
MVPN Vrf Target : None
MVPN Vrf Import : None
MVPN Vrf Export : None
Car. Sup C-VPN : Disabled
Label mode : vrf
BGP VPN Backup : Disabled
BGP Export Inactv : Disabled
LOG all events : Disabled

SAP Count : 1 SDP Bind Count : 0

-------------------------------------------------------------------------------
Service Access & Destination Points
-------------------------------------------------------------------------------
Identifier Type AdmMTU OprMTU Adm Opr
-------------------------------------------------------------------------------
sap:1/1/c6/1 null 1514 1514 Up Up

If the IGP instance used for the managed network redistributes routes into the IGP instance used for the management network, or vice versa, this is a finding.

Check Content Reference

M

Target Key

5746