Skip to content

Cisco NX OS Switch RTR Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.

    <VulnDiscussion>Packet loss can occur when an IGP adjacency is established and the switch begins forwarding packets using the new adjacency b...
    Rule Low Severity
  • SRG-NET-000193-RTR-000001

    <GroupDescription></GroupDescription>
    Group
  • The MPLS switch with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core switches.

    &lt;VulnDiscussion&gt;RSVP-TE can be used to perform constraint-based routing when building LSP tunnels within the network core that will support Q...
    Rule Low Severity
  • SRG-NET-000512-RTR-000004

    <GroupDescription></GroupDescription>
    Group
  • The Cisco MPLS switch must be configured to have TTL Propagation disabled.

    &lt;VulnDiscussion&gt;The head end of the label-switched path (LSP), the label edge switch (LER) will decrement the IP packet's time-to-live (TTL) ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules