Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-3034 | NET0400 | SV-3034r3_rule | ECSC-1 | Medium |
Description |
---|
A rogue router could send a fictitious routing update to convince a site's premise router to send traffic to an incorrect or even a rogue destination. This diverted traffic could be analyzed to learn confidential information of the site's network, or merely used to disrupt the network's ability to effectively communicate with other networks. |
STIG | Date |
---|---|
Perimeter L3 Switch Security Technical Implementation Guide | 2015-12-18 |
Check Text ( C-3489r4_chk ) |
---|
Review the device configuration to determine if authentication is configured for all IGP peers. If authentication is not configured for all IGP peers, this is a finding. |
Fix Text (F-3059r3_fix) |
---|
Configure authentication for all IGP peers. |