Skip to content

The Juniper perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an approved gateway service provider.

An XCCDF Rule

Description

Internet service providers (ISPs) use BGP to share route information with other autonomous systems (i.e., other ISPs and corporate networks). If the perimeter router was configured to BGP peer with an ISP, NIPRNet routes could be advertised to the ISP, thereby creating a backdoor connection from the internet to the NIPRNet.

ID
SV-217034r1050849_rule
Version
JUNI-RT-000290
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

This requirement is not applicable for the DODIN backbone.

Configure a static route on the perimeter router to reach the AS of a router connecting to an approved gateway as shown in the example below.

[edit routing-options]
set static route 0.0.0.0/0 next-hop x.x.x.x