Cisco IOS XE Router RTR Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-NET-000019-RTR-000009
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.
<VulnDiscussion>ISPs use BGP to share route information with other autonomous systems (i.e. other ISPs and corporate networks). If the perime...Rule High Severity -
SRG-NET-000019-RTR-000010
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to not redistribute static routes to an alternate gateway service provider into BGP or an Interior Gateway Protocol (IGP) peering with the NIPRNet or to other autonomous systems.
<VulnDiscussion>If the static routes to the alternate gateway are being redistributed into an Exterior Gateway Protocol or Interior Gateway P...Rule Low Severity -
SRG-NET-000205-RTR-000003
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DoD Instruction 8551.1.
<VulnDiscussion>Vulnerability assessments must be reviewed by the System Administrator, and protocols must be approved by the Information Ass...Rule Medium Severity -
SRG-NET-000205-RTR-000004
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to filter ingress traffic at the external interface on an inbound direction.
<VulnDiscussion>Access lists are used to separate data traffic into that which it will route (permitted packets) and that which it will not r...Rule Medium Severity -
SRG-NET-000205-RTR-000005
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.
<VulnDiscussion>Access lists are used to separate data traffic into that which it will route (permitted packets) and that which it will not r...Rule Medium Severity -
SRG-NET-000364-RTR-000111
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.
<VulnDiscussion>LLDP is a neighbor discovery protocol used to advertise device capabilities, configuration information, and device identity. ...Rule Low Severity -
SRG-NET-000364-RTR-000111
<GroupDescription></GroupDescription>Group -
The Cisco perimeter router must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.
<VulnDiscussion>CDP is a Cisco proprietary neighbor discovery protocol used to advertise device capabilities, configuration information, and ...Rule Low Severity -
SRG-NET-000364-RTR-000112
<GroupDescription></GroupDescription>Group -
The Cisco out-of-band management (OOBM) gateway router must be configured to transport management traffic to the Network Operations Center (NOC) via dedicated circuit, MPLS/VPN service, or IPsec tunnel.
<VulnDiscussion>Using dedicated paths, the OOBM backbone connects the OOBM gateway routers located at the edge of the managed network and at ...Rule Medium Severity -
SRG-NET-000205-RTR-000010
<GroupDescription></GroupDescription>Group -
The Cisco out-of-band management (OOBM) gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).
<VulnDiscussion>The OOBM network is an IP network used exclusively for the transport of OAM&P data from the network being managed to the ...Rule Medium Severity -
SRG-NET-000019-RTR-000011
<GroupDescription></GroupDescription>Group -
The Cisco out-of-band management (OOBM) gateway router must be configured to have separate Interior Gateway Protocol (IGP) instances for the managed network and management network.
<VulnDiscussion>If the gateway router is not a dedicated device for the OOBM network, implementation of several safeguards for containment of...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.