III - Administrative Classified
Rules and Groups employed by this XCCDF Profile
-
The perimeter router must be configured to block all packets with any IP options.
Packets with IP options are not fast routered and henceforth must be punted to the router processor. Hackers who initiate denial-of-service (DoS) attacks on routers commonly send large streams of p...Rule Medium Severity -
SRG-NET-000205-RTR-000016
Group -
The PE router must be configured to ignore or block all packets with any IP options.
Packets with IP options are not fast routered and therefore must be punted to the router processor. Hackers who initiate denial-of-service (DoS) attacks on routers commonly send large streams of pa...Rule Medium Severity -
SRG-NET-000018-RTR-000001
Group -
The Arista router must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.
Information flow control regulates where information is allowed to travel within a network and between interconnected networks. The flow of all network traffic must be monitored and controlled so i...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules