UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The Juniper multicast RP router must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of PIM and MSDP source-active entries.


Overview

Finding ID Version Rule ID IA Controls Severity
V-254040 JUEX-RT-000680 SV-254040r997535_rule Low
Description
MSDP peering between networks enables sharing of multicast source information. Enclaves with an existing multicast topology using PIM-SM can configure their RP routers to peer with MSDP routers. As a first step of defense against a denial-of-service (DoS) attack, all RP routers must limit the multicast forwarding cache to ensure that router resources are not saturated managing an overwhelming number of PIM and MSDP source-active entries.
STIG Date
Juniper EX Series Switches Router Security Technical Implementation Guide 2024-06-10

Details

Check Text ( C-57492r844151_chk )
Review the router configuration to determine if forwarding cache thresholds are defined.

[edit routing-options]
multicast {
forwarding-cache {
threshold {
suppress <1..200000>;
reuse <1..200000>;
log-warning ;
}
}
}

If the RP router is not configured to limit the multicast forwarding cache to ensure that its resources are not saturated, this is a finding.
Fix Text (F-57443r844152_fix)
Configure MSDP-enabled RP routers to limit the multicast forwarding cache for source-active entries.

set routing-options multicast forwarding-cache threshold suppress <1..200000>
set routing-options multicast forwarding-cache threshold reuse <1..200000>
set routing-options multicast forwarding-cache threshold log-warning