The Cisco BGP switch must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.
An XCCDF Rule
Description
Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a non-optimized path.
- ID
- SV-221107r999716_rule
- Version
- CISC-RT-000530
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Step 1: Configure a prefix list for containing all customer and local AS prefixes as shown in the example below:
SW1(config)# ip prefix-list FILTER_CORE_PREFIXES deny x.1.1.0/24 le 32
SW1(config)# ip prefix-list FILTER _CORE_PREFIXES deny x.1.2.0/24 le 32
SW1(config)# ip prefix-list FILTER _CORE_PREFIXES permit 0.0.0.0/0 ge 8