Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-254040 | JUEX-RT-000680 | SV-254040r997535_rule | Low |
Description |
---|
MSDP peering between networks enables sharing of multicast source information. Enclaves with an existing multicast topology using PIM-SM can configure their RP routers to peer with MSDP routers. As a first step of defense against a denial-of-service (DoS) attack, all RP routers must limit the multicast forwarding cache to ensure that router resources are not saturated managing an overwhelming number of PIM and MSDP source-active entries. |
STIG | Date |
---|---|
Juniper EX Series Switches Router Security Technical Implementation Guide | 2024-06-10 |
Check Text ( C-57492r844151_chk ) |
---|
Review the router configuration to determine if forwarding cache thresholds are defined. [edit routing-options] multicast { forwarding-cache { threshold { suppress <1..200000>; reuse <1..200000>; log-warning } } } If the RP router is not configured to limit the multicast forwarding cache to ensure that its resources are not saturated, this is a finding. |
Fix Text (F-57443r844152_fix) |
---|
Configure MSDP-enabled RP routers to limit the multicast forwarding cache for source-active entries. set routing-options multicast forwarding-cache threshold suppress <1..200000> set routing-options multicast forwarding-cache threshold reuse <1..200000> set routing-options multicast forwarding-cache threshold log-warning |