UCF STIG Viewer Logo

Cisco IOS XE Release 3 RTR Security Technical Implementation Guide


Overview

Date Finding Count (23)
2018-12-20 CAT I (High): 1 CAT II (Med): 22 CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC I - Mission Critical Public)

Finding ID Severity Title
V-74107 High The Cisco IOS XE router must protect an enclave connected to an Alternate Gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.
V-74103 Medium The Cisco IOS XE router must establish boundaries for IPv6 Admin-Local, IPv6 Site-Local, IPv6 Organization-Local scope, and IPv4 Local-Scope multicast traffic.
V-74105 Medium The Cisco IOS XE router must be configured so inactive interfaces are disabled.
V-74123 Medium The Cisco IOS XE router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding.
V-74121 Medium The Cisco IOS XE router must be configured so that any key used for authenticating Interior Gateway Protocol peers does not have a duration exceeding 180 days.
V-74119 Medium The Cisco IOS XE router must enable neighbor router authentication for control plane protocols.
V-74125 Medium The Cisco IOS XE router must be configured to disable non-essential capabilities.
V-74141 Medium The Cisco IOS XE router must only allow incoming communications from authorized sources to be routed to authorized destinations.
V-74127 Medium The Cisco IOS XE router must encrypt all methods of configured authentication for routing protocols.
V-74113 Medium The Cisco IOS XE router must enforce that Interior Gateway Protocol instances configured on the out-of-band management gateway router only peer with their own routing domain.
V-74111 Medium The Cisco IOS XE router must not redistribute static routes to alternate gateway service provider into an Exterior Gateway Protocol or Interior Gateway Protocol to the NIPRNet or to other Autonomous System.
V-74117 Medium The Cisco IOS XE router must enforce that any interface used for out-of-band management traffic is configured to be passive for the Interior Gateway Protocol that is utilized on that management interface.
V-74115 Medium The Cisco IOS XE router must enforce that the managed network domain and the management network domain are separate routing domains and the Interior Gateway Protocol instances are not redistributed or advertised to each other.
V-74135 Medium The Cisco IOS XE router must restrict BGP connections to known IP addresses of neighbor routers from trusted Autonomous Systems (AS).
V-74137 Medium The Cisco IOS XE router must configure the maximum hop limit value to at least 32.
V-74131 Medium The Cisco IOS XE router must manage excess bandwidth to limit the effects of packet flooding types of denial of service (DoS) attacks.
V-74133 Medium The Cisco IOS XE router must have IP source routing disabled.
V-74129 Medium The Cisco IOS XE router must ensure all Exterior Border Gateway Protocol (eBGP) routers are configured to use Generalized TTL Security Mechanism (GTSM).
V-74139 Medium The Cisco IOS XE router must protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.
V-74099 Medium The Cisco IOS XE router must bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
V-74109 Medium The Cisco IOS XE router must not be a BGP peer with a router from an Autonomous System belonging to any Alternate Gateway.
V-74097 Medium The Cisco IOS XE router must disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
V-74095 Medium The Cisco IOS XE router must enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.