HP FlexFabric Switch RTR Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
Digest of Updates +21 −22
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 21
- V-217504 Medium The HP FlexFabric Switch must be configured so inactive HP FlexFabric Switch interfaces are disabled.
- V-217505 Medium The HP FlexFabric Switch must not redistribute static routes to alternate gateway service provider into an Exterior Gateway Protocol or Interior Gateway Protocol to the NIPRNet or to other Autonomous System.
- V-217506 High The HP FlexFabric Switch must protect an enclave connected to an Alternate Gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.
- V-217507 Medium If Border Gateway Protocol (BGP) is enabled on the HP FlexFabric Switch, the HP FlexFabric Switch must not be a BGP peer with a HP FlexFabric Switch from an Autonomous System belonging to any Alternate Gateway (AG).
- V-217508 Medium The HP FlexFabric Switch must be configured to disable non-essential capabilities.
- V-217509 Medium The HP FlexFabric Switch must encrypt all methods of configured authentication for routing protocols.
- V-217510 Medium The HP FlexFabric Switch must use NIST-validated FIPS 140-2 cryptography to implement authentication encryption mechanisms for routing protocols.
- V-217511 Medium The HP FlexFabric Switch must enforce that Interior Gateway Protocol (IGP) instances configured on the out-of-band management gateway only peer with their own routing domain.
- V-217512 Medium The HP FlexFabric Switch must enforce that the managed network domain and the management network domain are separate routing domains and the Interior Gateway Protocol (IGP) instances are not redistributed or advertised to each other.
- V-217513 Medium The HP FlexFabric Switch must enforce that any interface used for out-of-band management traffic is configured to be passive for the Interior Gateway Protocol (IGP) that is utilized on that management interface.
- V-217514 Medium The HP FlexFabric Switch must protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.
- V-217515 Medium The HP FlexFabric Switch must only allow incoming communications from authorized sources to be routed to authorized destinations.
- V-217516 Medium The HP FlexFabric Switch must enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
- V-217517 Medium The HP FlexFabric Switch must disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
- V-217518 Medium The HP FlexFabric Switch must bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
- V-217519 Medium The HP FlexFabric Switch must establish boundaries for IPv6 Admin-Local, IPv6 Site-Local, IPv6 Organization-Local scope, and IPv4 Local-Scope multicast traffic.
- V-217520 Medium The HP FlexFabric Switch must enable neighbor authentication for all control plane protocols.
- V-217521 Medium The HP FlexFabric Switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding.
- V-217522 Medium The HP FlexFabric Switch must ensure all Exterior Border Gateway Protocol (eBGP) HP FlexFabric Switches are configured to use Generalized TTL Security Mechanism (GTSM).
- V-220132 Medium The HP FlexFabric Switch must manage excess bandwidth to limit the effects of packet flooding types of denial of service (DoS) attacks.
- V-220134 Medium The HP FlexFabric Switch must configure the maximum hop limit value to at least 32.
Removed rules 22
- V-65965 Medium The HP FlexFabric Switch must be configured so inactive HP FlexFabric Switch interfaces are disabled.
- V-66099 Medium The HP FlexFabric Switch must not redistribute static routes to alternate gateway service provider into an Exterior Gateway Protocol or Interior Gateway Protocol to the NIPRNet or to other Autonomous System.
- V-66101 High The HP FlexFabric Switch must protect an enclave connected to an Alternate Gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.
- V-66103 Medium If Border Gateway Protocol (BGP) is enabled on the HP FlexFabric Switch, the HP FlexFabric Switch must not be a BGP peer with a HP FlexFabric Switch from an Autonomous System belonging to any Alternate Gateway (AG).
- V-66105 Medium The HP FlexFabric Switch must restrict BGP connections to known IP addresses from trusted Autonomous Systems (AS).
- V-66107 Medium The HP FlexFabric Switch must be configured to disable non-essential capabilities.
- V-66109 Medium The HP FlexFabric Switch must enable neighbor authentication for all control plane protocols.
- V-66111 Medium The HP FlexFabric Switch must encrypt all methods of configured authentication for routing protocols.
- V-66113 Medium The HP FlexFabric Switch must use NIST-validated FIPS 140-2 cryptography to implement authentication encryption mechanisms for routing protocols.
- V-66115 Medium The HP FlexFabric Switch must enforce that Interior Gateway Protocol (IGP) instances configured on the out-of-band management gateway only peer with their own routing domain.
- V-66117 Medium The HP FlexFabric Switch must enforce that the managed network domain and the management network domain are separate routing domains and the Interior Gateway Protocol (IGP) instances are not redistributed or advertised to each other.
- V-66119 Medium The HP FlexFabric Switch must enforce that any interface used for out-of-band management traffic is configured to be passive for the Interior Gateway Protocol (IGP) that is utilized on that management interface.
- V-66121 Medium The HP FlexFabric Switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding.
- V-66123 Medium The HP FlexFabric Switch must manage excess bandwidth to limit the effects of packet flooding types of denial of service (DoS) attacks.
- V-66125 Medium The HP FlexFabric Switch must configure the maximum hop limit value to at least 32.
- V-66127 Medium The HP FlexFabric Switch must protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.
- V-66129 Medium The HP FlexFabric Switch must only allow incoming communications from authorized sources to be routed to authorized destinations.
- V-66131 Medium The HP FlexFabric Switch must enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
- V-66133 Medium The HP FlexFabric Switch must ensure all Exterior Border Gateway Protocol (eBGP) HP FlexFabric Switches are configured to use Generalized TTL Security Mechanism (GTSM).
- V-66135 Medium The HP FlexFabric Switch must disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
- V-66137 Medium The HP FlexFabric Switch must bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
- V-66139 Medium The HP FlexFabric Switch must establish boundaries for IPv6 Admin-Local, IPv6 Site-Local, IPv6 Organization-Local scope, and IPv4 Local-Scope multicast traffic.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000001
- Vuln IDs
-
- V-217504
- V-65965
- Rule IDs
-
- SV-217504r1137913_rule
- SV-80455
Checks: C-18726r368793_chk
Review the network topology diagram and determine which HP FlexFabric Switch interfaces should be inactive. If there are inactive HP FlexFabric Switch interfaces that are enabled, this is a finding. [HP]display current-configuration interface interface GigabitEthernet0/1 port link-mode route pim sm ip address 192.168.10.1 255.255.255.0 packet-filter 3010 inbound
Fix: F-18724r368794_fix
Disable inactive the HP FlexFabric Switch interface: [HP-GigabitEthernet0/1] shutdown
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000002
- Vuln IDs
-
- V-217505
- V-66099
- Rule IDs
-
- SV-217505r1137925_rule
- SV-80589
Checks: C-18727r368796_chk
Review the External/internal gateway protocol database on the HP FlexFabric Switch to ensure no static routes are being redistributed via these protocols. If there are static routes being re-distributed, this is a finding. [HP] display ospf lsdb OSPF Process 1 with HP FlexFabric Switch ID 5.9.2.0 Link State Database Area: 0.0.0.1 Type LinkState ID AdvHP FlexFabric Switch Age Len Sequence Metric HP FlexFabric Switch 1.1.1.1 1.1.1.1 1644 48 80000155 0 HP FlexFabric Switch 5.9.2.0 5.9.2.0 233 48 8000013E 0 HP FlexFabric Switch 2.2.2.2 2.2.2.2 294 72 8000014F 0 AS External Database Type LinkState ID AdvHP FlexFabric Switch Age Len Sequence Metric External 16.0.0.0 5.9.2.0 233 36 80000001 1 External 15.252.0.0 5.9.2.0 233 36 80000001 1 Note: In the example above we see two external entries with the advertising HP FlexFabric Switch as the HP FlexFabric Switch. This exists when the HP FlexFabric Switch is configured to redistribute static route.
Fix: F-18725r368797_fix
By default the HP FlexFabric switches do not redistribute static routes via External/Internak gateway protocols. If Static routes redistribution has been configure, use the command bellow to disable it. [HP] ospf 1 [HP-ospf-1] undo import-route static
- RMF Control
- AC-4
- Severity
- H
- CCI
- CCI-001414
- Version
- HFFS-RT-000003
- Vuln IDs
-
- V-217506
- V-66101
- Rule IDs
-
- SV-217506r1268284_rule
- SV-80591
Checks: C-18728r368799_chk
Review the configuration of each HP FlexFabric Switch interface connecting to an Alternate Gateway. Verify that the ACL configured to block unauthorized networks are configured on the interface. Verify each permit statement of the ingress filter only permits packets with destination addresses of the site's NIPRNet address space or a destination address belonging to the address block assigned by the Alternate Gateway network service provider. If the ACL is not configured to only permit packets with destination addresses within the sites address space, this is a finding. [HP]display interface gig0/1 interface GigabitEthernet0/1 port link-mode route ip address 192.168.10.1 255.255.255.0 packet-filter 3010 inbound
Fix: F-18726r368800_fix
Configure the ingress filter of the perimeter HP FlexFabric Switch connected to an Alternate Gateway to only permit packets with destination addresses of the site's NIPRNet address space or a destination address belonging to the address block assigned by the Alternate Gateway network service provider. [HP] acl advanced 3010 [HP-acl-ipv4-adv-3010] rule 1 permit ip destination 192.168.1.0 0.0.0.255 [HP-acl-ipv4-adv-3010] rule 2 permit ip destination 192.168.2.0 0.0.0.255 [HP-acl-ipv4-adv-3010] rule 3 permit ip destination 192.168.3.0 0.0.0.255 [HP-acl-ipv4-adv-3010] rule 4 permit ip destination 192.168.4.0 0.0.0.255 [HP-acl-ipv4-adv-3010] rule 5 deny ip destination any [HP] interface gig0/1 [HP-GigabitEthernet0/1] packet-filter 3010 inbound
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000004
- Vuln IDs
-
- V-217507
- V-66103
- Rule IDs
-
- SV-217507r1137922_rule
- SV-80593
Checks: C-18729r368802_chk
Review the configuration of the HP FlexFabric Switch connecting to the AG. Verify there are no BGP neighbors configured to the remote AS that belongs to the AG service provider. There should be no BGP peers displayed. If there are BGP neighbors configured that belong to the AG service provider, this is a finding. [HP] display bgp peer ipv4 BGP local FlexFabric Switch ID: 2.2.2.0 Local AS number: 1472 Total number of peers: 1 Peers in established state: 0 * - Dynamically created peer Peer AS MsgRcvd MsgSent OutQ PrefRcv Up/Down State
Fix: F-18727r368803_fix
Configure a static route on the perimeter HP FlexFabric Switch to reach the AS of a HP FlexFabric Switch connecting to an Alternate Gateway. [HP] ip route-static 11.11.11.0 16 12.12.12.2
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- HFFS-RT-000006
- Vuln IDs
-
- V-217508
- V-66107
- Rule IDs
-
- SV-217508r382903_rule
- SV-80597
Checks: C-18730r368805_chk
Review the configuration to verify that non-essential services are not enabled, if these services are enabled, this is a finding: [HP] display ftp-server FTP is not configured. [HP] display current-configuration | include telnet Note: When Telnet server is enabled, the output for this command is telnet server enable.
Fix: F-18728r368806_fix
Disable unsecure protocols and services on the HP FlexFabric Switch: [HP] undo ftp server enable [HP] undo telnet server enable Note: By default, both FTP and Telnet services are disabled.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- HFFS-RT-000011
- Vuln IDs
-
- V-217509
- V-66111
- Rule IDs
-
- SV-217509r385516_rule
- SV-80601
Checks: C-18731r368808_chk
Verify the HP FlexFabric Switch configuration to ensure that it is using a NIST validated FIPS 140-2 cryptography encryption mechanism by implementing OSPFv3 with IPsec. [HP] display current-configuration interface interface GigabitEthernet0/0 port link-mode route description R1 ACTIVE combo enable copper ospfv3 200 area 0.0.0.0 ospfv3 ipsec-profile jitc ipv6 address 2115:B:1::3E/126 If the routing protocol authentication mechanism is not a validated FIPS 140-2 cryptography, this is a finding. Note: OSPFv3 requires IPsec to enable authentication using either the IPv6 Authentication Header (AH) or the Encapsulating Security Payload (ESP) header.
Fix: F-18729r368809_fix
Configure the HP FlexFabric Switch to authenticate OSPFv3 packets: [HP]ipsec transform-set jitcipsecprop [HP-ipsec-transform-set-jitcipsecprop] [HP-ipsec-transform-set-jitcipsecprop] ipsec transform-set jitcipsecprop [HP-ipsec-transform-set-jitcipsecprop] encapsulation-mode transport [HP-ipsec-transform-set-jitcipsecprop] esp encryption-algorithm aes-cbc-256 [HP-ipsec-transform-set-jitcipsecprop] esp authentication-algorithm sha1 [HP-ipsec-transform-set-jitcipsecprop] quit [HP] ipsec profile jitc manual [HP-ipsec-profile-manual-jitc] [HP-ipsec-profile-manual-jitc] ipsec profile jitc manual [HP-ipsec-profile-manual-jitc] transform-set jitcipsecprop [HP-ipsec-profile-manual-jitc] sa spi inbound esp 256 [HP-ipsec-profile-manual-jitc] sa string-key inbound esp simple test123 [HP-ipsec-profile-manual-jitc] sa spi outbound esp 256 [HP-ipsec-profile-manual-jitc] sa string-key outbound esp simple test123 [HP-ipsec-profile-manual-jitc] quit [HP] interface gigabitethernet 0/1 [HP--GigabitEthernet0/1] ospfv3 ipsec-profile jitc
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- HFFS-RT-000012
- Vuln IDs
-
- V-217510
- V-66113
- Rule IDs
-
- SV-217510r385516_rule
- SV-80603
Checks: C-18732r368811_chk
Verify the HP FlexFabric Switch configuration to ensure that it is using a NIST validated FIPS 140-2 cryptography encryption mechanism by implementing OSPFv3 with IPsec. [HP] display current-configuration interface interface GigabitEthernet0/0 port link-mode route description R1 ACTIVE combo enable copper ospfv3 200 area 0.0.0.0 ospfv3 ipsec-profile jitc ipv6 address 2115:B:1::3E/126 If the routing protocol authentication mechanism is not a validated FIPS 140-2 cryptography, this is a finding. Note: OSPFv3 requires IPsec to enable authentication using either the IPv6 Authentication Header (AH) or the Encapsulating Security Payload (ESP) header.
Fix: F-18730r368812_fix
Configure the HP FlexFabric Switch to authenticate OSPFv3 packets: [HP]ipsec transform-set jitcipsecprop [HP-ipsec-transform-set-jitcipsecprop] [HP-ipsec-transform-set-jitcipsecprop] ipsec transform-set jitcipsecprop [HP-ipsec-transform-set-jitcipsecprop] encapsulation-mode transport [HP-ipsec-transform-set-jitcipsecprop] esp encryption-algorithm aes-cbc-256 [HP-ipsec-transform-set-jitcipsecprop] esp authentication-algorithm sha1 [HP-ipsec-transform-set-jitcipsecprop] quit [HP] ipsec profile jitc manual [HP-ipsec-profile-manual-jitc] [HP-ipsec-profile-manual-jitc] ipsec profile jitc manual [HP-ipsec-profile-manual-jitc] transform-set jitcipsecprop [HP-ipsec-profile-manual-jitc] sa spi inbound esp 256 [HP-ipsec-profile-manual-jitc] sa string-key inbound esp simple test123 [HP-ipsec-profile-manual-jitc] sa spi outbound esp 256 [HP-ipsec-profile-manual-jitc] sa string-key outbound esp simple test123 [HP-ipsec-profile-manual-jitc] quit [HP] interface gigabitethernet 0/1 [HP--GigabitEthernet0/1] ospfv3 ipsec-profile jitc
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000014
- Vuln IDs
-
- V-217511
- V-66115
- Rule IDs
-
- SV-217511r1137928_rule
- SV-80605
Checks: C-18733r368814_chk
Review the configuration to verify the management interface belongs to a different OSPF instance (process) than the production network. If the management interface does not belong to a different OSPF instance, this is a finding.
Fix: F-18731r368815_fix
If OSPF is used for the management network, configure the management interface to belong to a different OSPF instance than the production network.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000015
- Vuln IDs
-
- V-217512
- V-66117
- Rule IDs
-
- SV-217512r1137930_rule
- SV-80607
Checks: C-18734r368817_chk
Review the configuration to verify the management interface belongs to a different OSPF instance (process) than the production network. If the management interface does not belong to a different OSPF instance, this is a finding.
Fix: F-18732r368818_fix
If OSPF is used for the management network, configure the management interface to belong to a different OSPF instance than the production network.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000016
- Vuln IDs
-
- V-217513
- V-66119
- Rule IDs
-
- SV-217513r1137932_rule
- SV-80609
Checks: C-18735r368820_chk
Review the configuration to verify the OOBM interface belongs to a different OSPF instance (process) than the production network. If the management interface does not belong to a different OSPF instance, this is a finding. Note: By default an OOBM interface is passive to a routing protocol.
Fix: F-18733r368821_fix
If OSPF is used for the management network, configure the OOBM interface to belong to a different OSPF instance than the production network.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- HFFS-RT-000020
- Vuln IDs
-
- V-217514
- V-66127
- Rule IDs
-
- SV-217514r856529_rule
- SV-80617
Checks: C-18736r368823_chk
Verify that there is a control plane policy configured on the HP FlexFabric to rate limit control plane traffic using the following command: display qos policy control-plane slot 1. If the HP FlexFabric Switch is not configured to rate limit control plane traffic, this is a finding.
Fix: F-18734r368824_fix
1. Classify control plane traffic traffic classifier Class-Control-Plane operator or if-match control-plane protocol ospf bgp 2. Create policer to rate limit the control plane traffic traffic behavior Police-Control-Plane car cir nnn cbs nnnn ebs 0 green pass red discard yellow pass 3. Create QoS policy using the traffic classifier and traffic behavior qos policy Policy-Control-Plane classifier Class-Control-Plane behavior Police-Control-Plane 4. Apply the QoS policy to rate limit control-plane traffic control-plane slot 1 qos apply policy Policy-Control-Plane inbound
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-002403
- Version
- HFFS-RT-000021
- Vuln IDs
-
- V-217515
- V-66129
- Rule IDs
-
- SV-217515r856530_rule
- SV-80619
Checks: C-18737r368826_chk
Review the HP FlexFabric Switch configuration to determine if the switch only allows incoming communications from authorized sources to be routed to authorized destinations. This requirement can be met by applying an ingress filter to an external-facing interface as shown in the following example: acl number 3001 rule 1 deny ip source 192.168.3.121 0 rule 2 permit ip source 192.100.1.0 0.0.0.255 destination 192.200.2.0 0.0.0.255 interface Ten-GigabitEthernet1/0/21 ip address 102.17.17.2 255.255.255.252 packet-filter 3001 inbound If the HP FlexFabric Switch allows incoming communications from unauthorized sources or to unauthorized destinations, this is a finding.
Fix: F-18735r368827_fix
Configure the HP FlexFabric Switch to only allow incoming communications from authorized sources to be routed to authorized destinations.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000022
- Vuln IDs
-
- V-217516
- V-66131
- Rule IDs
-
- SV-217516r1137907_rule
- SV-80621
Checks: C-18738r368829_chk
Review the HP FlexFabric Switch configuration to determine if the switch enforces approved authorizations for controlling the flow of information between interconnected networks or VLANs in accordance with applicable policy. This requirement can be met through the use of IP access control lists which are applied to specific interfaces inbound or outbound as show in the following example: acl number 3001 rule 1 deny ip source 192.168.3.121 0 rule 2 permit ip source 192.100.1.0 0.0.0.255 destination 192.200.2.0 0.0.0.255 interface Ten-GigabitEthernet1/0/21 ip address 102.17.17.2 255.255.255.252 packet-filter 3001 inbound If the switch does not enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy, this is a finding.
Fix: F-18736r368830_fix
Configure the switch to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy using ACLs that are applied to the appropriate interfaces.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000024
- Vuln IDs
-
- V-217517
- V-66135
- Rule IDs
-
- SV-217517r1268285_rule
- SV-80625
Checks: C-18739r368832_chk
Review the multicast topology diagram and determine which HP FlexFabric Switch interfaces should have Protocol Independent Multicast enabled. Disable PIM on interfaces that should not have it enabled. If PIM is enabled interfaces that are not required to support multicast routing, this is a finding. [HP]display current-configuration interface interface GigabitEthernet0/1 port link-mode route pim sm ip address 192.168.10.1 255.255.255.0 packet-filter 3010 inbound [HP FlexFabric SwitchD] display pim neighbor Total Number of Neighbors = 3 Neighbor Interface Uptime Expires Dr-Priority 192.168.10.2 GE0/1 00:02:22 00:01:27 1
Fix: F-18737r368833_fix
Disable PIM on the HP FlexFabric Switch interfaces that should not have it enabled: [HP-GigabitEthernet0/1] undo pim sm
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000025
- Vuln IDs
-
- V-217518
- V-66137
- Rule IDs
-
- SV-217518r1137911_rule
- SV-80627
Checks: C-18740r368835_chk
Review the multicast topology diagram and determine if the HP FlexFabric Switch interfaces are enabled for IPv4 or IPv6 multicast routing. If the HP FlexFabric Switch is enabled for multicast routing, verify all interfaces enabled for PIM have a neighbor filter bound to the interface. The neighbor filter must only accept PIM control plane traffic from the documented PIM neighbors. If a PIM neighbor filter is not configured on all multicast-enabled interfaces, this is a finding. display interface GigabitEthernet 0/1 interface GigabitEthernet0/1 port link-mode route description IUT 4GE-HMIM ip address 15.252.78.69 255.255.255.0 pim sm pim neighbor-policy 2000 ipv6 pim sm ipv6 pim neighbor-policy 2000 [HP]display acl 2000 Basic ACL 2000, named -none-, 3 rules, ACL's step is 5 rule 0 permit source 224.200.100.10 0 rule 5 permit source 224.200.101.11 0 rule 10 deny
Fix: F-18738r368836_fix
Configure neighbor filters to only accept PIM control plane traffic from documented PIM neighbors. Bind neighbor filters to all PIM enabled interfaces using the example bellow. acl basic 2000 rule 0 permit source 224.200.100.10 0 rule 5 permit source 224.200.101.11 0 rule 10 deny source any interface GigabitEthernet0/1 pim neighbor-policy 2000
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- HFFS-RT-000026
- Vuln IDs
-
- V-217519
- V-66139
- Rule IDs
-
- SV-217519r1137912_rule
- SV-80629
Checks: C-18741r368838_chk
Review the multicast topology diagram to determine if there are any documented Admin-Local (FFx4::/16), Site-Local (FFx5::/16), or Organization-Local (FFx8::/16) multicast boundaries for IPv6 traffic or any Local-Scope (239.255.0.0/16) boundaries for IPv4 traffic. Verify the appropriate boundaries are configured on the applicable multicast-enabled interfaces. If appropriate multicast scope boundaries have not been configured, this is a finding. [HP] display current-configuration interface GigabitEthernet 0/2 interface GigabitEthernet0/2 port link-mode route description OVERSUBSCRIBE ip address 201.6.36.1 255.255.255.0 multicast boundary 239.255.0.0 16 ipv6 multicast boundary scope 4 ipv6 multicast boundary scope 5 ipv6 multicast boundary scope 8 ipv6 address 2115:C:24::1/120
Fix: F-18739r368839_fix
Configure the appropriate boundaries to contain packets addressed within the administratively scoped zone. Defined multicast addresses are FFx4::/16, FFx5::/16, FFx8::/16, and 239.255.0.0/16. Enable ip multicast globally [HP] ipv6 multicast routing Specify the IPv6 multicast boundary on multicast enabled interface [HP] interface gig 0/2 [HP-GigabitEthernet0/2] ipv6 multicast boundary scope 4 [HP-GigabitEthernet0/2] ipv6 multicast boundary scope 5 [HP-GigabitEthernet0/2] ipv6 multicast boundary scope 8 specify the IPv4 multicast boundary on multicast enabled interfaces [HP-GigabitEthernet0/2] multicast boundary 239.255.0.0 16
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- HFFS-RT-000010
- Vuln IDs
-
- V-217520
- V-66109
- Rule IDs
-
- SV-217520r945861_rule
- SV-80599
Checks: C-18742r388927_chk
Review the HP FlexFabric Switch configuration; for every protocol that affects the routing or forwarding tables (where information is exchanged between neighbors), verify that neighbor HP FlexFabric Switch authentication is enabled. If neighbor authentication for all router control plane protocols is not configured, this is a finding. The information below shows OSPF and OSPFv3 authentication is enabled on interface gigabit ethernet 0/0 [HP] display current-configuration interface GigabitEthernet 0/0 # interface GigabitEthernet0/0 port link-mode route description R1 ACTIVE combo enable copper ip address 201.6.1.62 255.255.255.252 ospf authentication-mode md5 1 cipher ********** ospfv3 200 area 0.0.0.0 ospfv3 ipsec-profile jitc ipv6 address 2115:B:1::3E/126
Fix: F-18740r388928_fix
The following example shows how to configure the network device to authenticate OSPF and OSPFv3 packets with its peers. OSPF configuration: [HP] ospf 200 [HP-ospf-200] area 0.0.0.0 [HP-ospf-200-area-0.0.0.0] authentication-mode md5 1 cipher ************* [HP-ospf-200-area-0.0.0.0] network 201.6.1.60 0.0.0.3 OSPFv3 Configuration [HP] ospfv3 200 [HP-ospf-200] area 0.0.0.0 IPsec profile configuration for OSPFv3 [HP] ipsec profile jitc manual [HP--ipsec-profile-manual-jitc] transform-set jitcipsecprop [HP--ipsec-profile-manual-jitc] sa spi inbound esp 256 [HP--ipsec-profile-manual-jitc] sa string-key inbound esp simple 2!HPAdmin123123 [HP--ipsec-profile-manual-jitc] sa spi outbound esp 256 [HP--ipsec-profile-manual-jitc] sa string-key outbound esp simple 2!HPAdmin123123 Interface configuration interface GigabitEthernet0/0 port link-mode route description R1 ACTIVE combo enable copper ip address 201.6.1.62 255.255.255.252 ospf authentication-mode md5 1 cipher $c$3$6v1tbSQA2aWAzrgzm36LZrBbmS+jUeg= ospfv3 200 area 0.0.0.0 ospfv3 ipsec-profile jitc ipv6 address 2115:B:1::3E/126
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001094
- Version
- HFFS-RT-000017
- Vuln IDs
-
- V-217521
- V-66121
- Rule IDs
-
- SV-217521r945858_rule
- SV-80611
Checks: C-18743r388930_chk
Display the switch configuration to verify that either the command ip urpf strict has been configured or an egress filter has been configured on all internal-facing interfaces to drop all outbound packets with an illegitimate source address. If uRPF or an egress filter to restrict the switch from accepting outbound IP packets that contain an illegitimate address in the source address field has not been configured on all internal-facing interfaces, this is a finding.
Fix: F-18741r388931_fix
Configure the global command ip urpf strict on the switch.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- HFFS-RT-000023
- Vuln IDs
-
- V-217522
- V-66133
- Rule IDs
-
- SV-217522r856532_rule
- SV-80623
Checks: C-18744r388933_chk
Review the HP FlexFabric Switch configuration. If the HP FlexFabric Switch is not configured to use GTSM for all eBGP peering sessions, this is a finding. [HP] display current-configuration # bgp 2000 graceful-restart peer 10.10.10.1 as-number 2000 peer 10.10.10.1 ttl-security hops 254 peer 201.6.1.193 as-number 1473 peer 201.6.1.193 route-update-interval 0 peer 201.6.1.193 password cipher $c$3$6jyBDW1nVs/F0410R54zhmhD1HYhs5I= peer 2115:B:1::C1 as-number 1473 peer 2115:B:1::C1 route-update-interval 0
Fix: F-18742r388934_fix
Configure all eBGP peering sessions to use GTSM. [HP] bgp 2000 [HP-bgp] peer 192.178.19.1 as-number 2100 [HP-bgp] peer 192.178.19.1 ttl-security hops 254
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- HFFS-RT-000018
- Vuln IDs
-
- V-220132
- V-66123
- Rule IDs
-
- SV-220132r539408_rule
- SV-80613
Checks: C-21846r388528_chk
Interview the system administrator to determine the requirements for bandwidth and traffic prioritization. Display the HP FlexFabric Switch configuration to ensure that the HP FlexFabric Switch is configured with these requirements. If excess bandwidth is not managed to limit the effects of packet flooding types of denial of service (DoS) attacks, this is a finding [HP] display current interface serial10/0 # interface Serial10/0 description IUT 2M-SERIAL virtualbaudrate 2048000 qos reserved-bandwidth pct 100 qos flow-interval 1 qos apply policy JITC-2M-SERIAL outbound undo ipv6 nd ra halt #
Fix: F-21840r388529_fix
Implement a mechanism for traffic prioritization and bandwidth reservation. This mechanism must enforce the traffic priorities specified by the Combatant Commanders/Services/Agencies. traffic classifier VOICE operator or if-match dscp 49 # traffic behavior VOICE-2M-SERIAL traffic-policy NEST_EF gts cir 441 cbs 2757 ebs 0 queue-length 50 queue ef bandwidth pct 25 cbs-ratio 25 # traffic classifier VIDEO operator or if-matdscp 39 # traffic behavior VIDEO-2M-SERIAL traffic-policy NEST_AF gts cir 301 cbs 1882 ebs 0 queue-length 50 queue af bandwidth pct 15 # traffic classifier DATA operator or if-match dscp 11 # traffic behavior DATA-2M-SERIAL traffic-policy NEST_AF gts cir 778 cbs 4863 ebs 0 queue-length 50 queue af bandwidth pct 40 # qos policy JITC-2M-SERIAL classifier default-class behavior be-bal classifier VOICE behavior VOICE-2M-SERIAL classifier VIDEO behavior VIDEO-2M-SERIAL classifier DATA behavior DATA-2M-SERIAL # interface Serial10/0 description IUT 2M-SERIAL virtualbaudrate 2048000 qos reserved-bandwidth pct 100 qos flow-interval 1 qos apply policy JITC-2M-SERIAL outbound undo ipv6 nd ra halt
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001097
- Version
- HFFS-RT-000019
- Vuln IDs
-
- V-220134
- V-66125
- Rule IDs
-
- SV-220134r539410_rule
- SV-80615
Checks: C-21848r388839_chk
Review the HP FlexFabric Switch configuration to determine if the maximum hop limit has been configured. If the maximum hop limit is not configured, this is a finding. If it has been configured, then it must be set to at least 32; otherwise this is a finding. [5900CP]display current-configuration | i hop-limit ipv6 hop-limit 255 Note: The default value for the maximum hop limit is 64.
Fix: F-21842r388840_fix
If the max hop set is not configured then use the following command to configure it: [HP] ipv6 hop-limit 255