Cisco IOS XE Switch RTR Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-NET-000205-RTR-000016
Group -
SRG-NET-000018-RTR-000008
Group -
SRG-NET-000193-RTR-000113
Group -
SRG-NET-000193-RTR-000114
Group -
SRG-NET-000193-RTR-000112
Group -
The Cisco switch must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.
DoS is a condition when a resource is not available for legitimate users. Packet flooding distributed denial-of-service (DDoS) attacks are referred to as volumetric attacks and have the objective o...Rule Medium Severity -
SRG-NET-000019-RTR-000003
Group -
The Cisco multicast switch must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
If multicast traffic is forwarded beyond the intended boundary, it is possible that it can be intercepted by unauthorized or unintended personnel. Limiting where, within the network, a given multic...Rule Medium Severity -
SRG-NET-000019-RTR-000004
Group -
SRG-NET-000019-RTR-000005
Group -
The Cisco multicast edge switch must be configured to establish boundaries for administratively scoped multicast traffic.
If multicast traffic is forwarded beyond the intended boundary, it is possible that it can be intercepted by unauthorized or unintended personnel. Administrative scoped multicast addresses are loc...Rule Low Severity -
SRG-NET-000362-RTR-000120
Group -
The Cisco multicast Rendezvous Point (RP) switch must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of Protocol Independent Multicast (PIM) and Multicast Source Discovery Protocol (MSDP) source-active entries.
MSDP peering between networks enables sharing of multicast source information. Enclaves with an existing multicast topology using PIM-SM can configure their RP switches to peer with MSDP switches. ...Rule Low Severity -
SRG-NET-000019-RTR-000013
Group -
SRG-NET-000019-RTR-000014
Group -
The Cisco multicast Rendezvous Point (RP) switch must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the Designated Cisco switch (DR) for any undesirable multicast groups.
Real-time multicast traffic can entail multiple large flows of data. An attacker can flood a network segment with multicast packets, over-using the available bandwidth and thereby creating a denial...Rule Low Severity -
SRG-NET-000362-RTR-000121
Group -
SRG-NET-000364-RTR-000114
Group -
SRG-NET-000364-RTR-000115
Group -
SRG-NET-000362-RTR-000122
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.