Skip to content

HP FlexFabric Switch RTR Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000019-RTR-000011

    Group
  • SRG-NET-000019-RTR-000009

    Group
  • The HP FlexFabric Switch must protect an enclave connected to an Alternate Gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.

    Enclaves with Alternate Gateway (AG) connections must take additional steps to ensure there is no compromise on the enclave network or NIPRNet. Without verifying the destination address of traffic ...
    Rule High Severity
  • SRG-NET-000019-RTR-000010

    Group
  • If Border Gateway Protocol (BGP) is enabled on the HP FlexFabric Switch, the HP FlexFabric Switch must not be a BGP peer with a HP FlexFabric Switch from an Autonomous System belonging to any Alternate Gateway (AG).

    The perimeter router will not use a routing protocol to advertise NIPRNet addresses to Alternate Gateways. Most ISPs use Border Gateway Protocol (BGP) to share route information with other autonomo...
    Rule Medium Severity
  • SRG-NET-000131-RTR-000035

    Group
  • The HP FlexFabric Switch must be configured to disable non-essential capabilities.

    A compromised router introduces risk to the entire network infrastructure as well as data resources that are accessible via the network. The perimeter defense has no oversight or control of attacks...
    Rule Medium Severity
  • SRG-NET-000025-RTR-000020

    Group
  • SRG-NET-000168-RTR-000077

    Group
  • SRG-NET-000168-RTR-000078

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules