UCF STIG Viewer Logo

The router must reject any outbound IP packets that contain an illegitimate address in the source address field through the enabling of uRPF strict mode or egress filter.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000024-RTR-000018 SRG-NET-000024-RTR-000018 SRG-NET-000024-RTR-000018_rule Low
Description
Unicast Reverse Path Forwarding (uRPF) provides an IP address spoof protection capability. When uRPF is enabled in strict mode, the packet must be received on the interface that the router would use to forward the return packet.
STIG Date
Router Security Requirements Guide 2013-07-30

Details

Check Text ( C-SRG-NET-000024-RTR-000018_chk )
Review the router configuration and validate uRPF or an egress filter has been configured on all internal interfaces. If uRPF or an egress filter has not been configured on all internal interfaces, this is a finding.

Fix Text (F-SRG-NET-000024-RTR-000018_fix)
Configure the router to reject any outbound IP packet that contains an illegitimate address in the source address field by enabling uRPF Strict mode or an egress filter.