Skip to content

The Cisco BGP router must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.

An XCCDF Rule

Description

Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a non-optimized path.

ID
SV-216781r531087_rule
Version
CISC-RT-000530
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Step 1: Configure a prefix set containing the IP core prefix as shown below.

RP/0/0/CPU0:R2(config)#prefix-set 

Step 2: Configure a prefix set containing the current Bogon prefixes as shown below.