The Cisco BGP switch must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).
An XCCDF Rule
Description
Accepting route advertisements belonging to the local AS can result in traffic looping or being black-holed, or at a minimum, using a non-optimized path.
- ID
- SV-221104r999713_rule
- Version
- CISC-RT-000500
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the switch to reject inbound route advertisements for any prefixes belonging to the local AS.
Step 1: Add to the prefix filter list those prefixes belonging to the local autonomous system.
SW1(config)# ip prefix-list PREFIX_FILTER seq 74 deny x.13.1.0/24 le 32