The Juniper BGP router must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.
An XCCDF Rule
Description
Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a nonoptimized path.
- ID
- SV-254015r844078_rule
- Version
- JUEX-RT-000430
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure all eBGP routers to filter outbound route advertisements belonging to the IP core.
For example:
set policy-options prefix-list ip-core-ipv4 192.0.2.0/24
set policy-options prefix-list ip-core-ipv6 2001:db8:2::/64
set policy-options policy-statement advertise-bgp-prefix term exclude-ipv4-core from prefix-list ip-core-ipv4