Skip to content

Cisco IOS Router RTR Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Cisco perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an approved gateway service provider.

    ISPs use BGP to share route information with other autonomous systems (i.e., other ISPs and corporate networks). If the perimeter router was configured to BGP peer with an ISP, NIPRNet routes could...
    Rule High Severity
  • SRG-NET-000019-RTR-000010

    Group
  • The Cisco perimeter router must be configured to not redistribute static routes to an approved gateway service provider into BGP, an IGP peering with the NIPRNet, or other autonomous systems.

    If the static routes to the approved gateway are being redistributed into an Exterior Gateway Protocol or Interior Gateway Protocol to a NIPRNet gateway, this could make traffic on NIPRNet flow to ...
    Rule Low Severity
  • SRG-NET-000205-RTR-000003

    Group
  • SRG-NET-000205-RTR-000004

    Group
  • The Cisco perimeter router must be configured to filter ingress traffic at the external interface on an inbound direction.

    Access lists are used to separate data traffic into that which it will route (permitted packets) and that which it will not route (denied packets). Secure configuration of routers makes use of acce...
    Rule Medium Severity
  • SRG-NET-000205-RTR-000005

    Group
  • SRG-NET-000364-RTR-000111

    Group
  • The Cisco perimeter router must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.

    LLDP is a neighbor discovery protocol used to advertise device capabilities, configuration information, and device identity. LLDP is media- and protocol-independent as it runs over layer 2; therefo...
    Rule Low Severity
  • SRG-NET-000364-RTR-000111

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules