Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000024-RTR-000018 | SRG-NET-000024-RTR-000018 | SRG-NET-000024-RTR-000018_rule | Low |
Description |
---|
Unicast Reverse Path Forwarding (uRPF) provides an IP address spoof protection capability. When uRPF is enabled in strict mode, the packet must be received on the interface that the router would use to forward the return packet. |
STIG | Date |
---|---|
Router Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000024-RTR-000018_chk ) |
---|
Review the router configuration and validate uRPF or an egress filter has been configured on all internal interfaces. If uRPF or an egress filter has not been configured on all internal interfaces, this is a finding. |
Fix Text (F-SRG-NET-000024-RTR-000018_fix) |
---|
Configure the router to reject any outbound IP packet that contains an illegitimate address in the source address field by enabling uRPF Strict mode or an egress filter. |