Router Security Requirements Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +28 −26
Comparison against the immediately-prior release (V2R0.1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 28
- V-55721 Medium The router must enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
- V-55723 Medium The router must disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
- V-55727 Medium The router must bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
- V-55729 Medium The router must establish boundaries for IPv6 Admin-Local, IPv6 Site-Local, IPv6 Organization-Local scope, and IPv4 Local-Scope multicast traffic.
- V-55731 Medium The router must be configured so inactive router interfaces are disabled.
- V-55733 Medium The router must protect an enclave connected to an Alternate Gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.
- V-55735 Medium If Border Gateway Protocol (BGP) is enabled on the router, the router must not be a BGP peer with a router from an Autonomous System belonging to any Alternate Gateway.
- V-55739 Medium The router must not redistribute static routes to alternate gateway service provider into an Exterior Gateway Protocol or Interior Gateway Protocol to the NIPRNet or to other Autonomous System.
- V-55741 Medium The router must enforce that Interior Gateway Protocol instances configured on the out-of-band management gateway router only peer with their own routing domain.
- V-55747 Medium The router must enforce that the managed network domain and the management network domain are separate routing domains and the Interior Gateway Protocol instances are not redistributed or advertised to each other.
- V-55749 Medium The router must enforce that any interface used for out-of-band management traffic is configured to be passive for the Interior Gateway Protocol that is utilized on that management interface.
- V-55753 Medium The router must enforce information flow control using explicit security attributes (for example, IP addresses, port numbers, protocol, Autonomous System, or interface) on information, source, and destination objects.
- V-55757 Medium The router must enable neighbor router authentication for control plane protocols.
- V-55759 Medium The router must be configured so that any key used for authenticating Interior Gateway Protocol peers does not have a duration exceeding 180 days.
- V-55761 Medium The router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding.
- V-55763 Medium The router must be configured to disable non-essential capabilities.
- V-55765 Medium The router must encrypt all methods of configured authentication for routing protocols.
- V-55767 Medium The router must use NIST-validated FIPS 140-2 cryptography to implement authentication encryption mechanisms for routing protocols.
- V-55769 Medium The router must ensure all Exterior Border Gateway Protocol (eBGP) routers are configured to use Generalized TTL Security Mechanism (GTSM).
- V-55771 Medium The router must manage excess bandwidth to limit the effects of packet flooding types of denial of service (DoS) attacks.
- V-55773 Medium The router must have IP source routing disabled.
- V-55775 Medium The router must restrict BGP connections to known IP addresses of neighbor routers from trusted Autonomous Systems (AS).
- V-55777 Medium The router must configure the maximum hop limit value to at least 32.
- V-55779 Medium The router must stop forwarding traffic or maintain the configured security policies upon the failure of the following actions: system initialization, shutdown, or system abort.
- V-55781 Medium The router must protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.
- V-55785 Medium The router must only allow incoming communications from authorized sources to be routed to authorized destinations.
- V-55789 Medium The router must fail securely in the event of an operational failure.
- V-55791 Medium The router must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including NSA configuration guides, Communications Tasking Orders (CTOs), and Directive-Type Memorandums (DTMs).
Removed rules 26
- SRG-NET-000019-RTR-000002 Medium The router must enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
- SRG-NET-000019-RTR-000003 Medium The router must disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
- SRG-NET-000019-RTR-000004 Medium The router must bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
- SRG-NET-000019-RTR-000005 Medium The router must establish boundaries for Admin-Local or Site-Local scope multicast traffic.
- SRG-NET-000019-RTR-000007 Medium The router must be configured so inactive router interfaces are disabled.
- SRG-NET-000019-RTR-000008 Medium The router must be configured with a filter to deny all traffic applied to all inactive interfaces.
- SRG-NET-000019-RTR-000009 Medium The router must protect an enclave connected to an Alternate Gateway by using an inbound filter that only permits packets with destination addresses within the site's address space.
- SRG-NET-000019-RTR-000010 Medium If BGP is enabled on the router, the router must not be a BGP peer with a router from an Autonomous System belonging to any Alternate Gateway.
- SRG-NET-000019-RTR-000011 Medium The router must not redistribute static routes to alternate gateway service provider into an EGP or IGP to the NIPRNet or to other Autonomous System.
- SRG-NET-000019-RTR-000012 Medium The router must enforce that IGP instances configured on the Out Of Band Management (OOBM) gateway router only peer with their own routing domain.
- SRG-NET-000019-RTR-000013 Medium The router must enforce that the managed network domain and the management network domain are separate routing domains and the IGP instances are not redistributed or advertised to each other.
- SRG-NET-000019-RTR-000014 Medium The router must enforce that any interface used for OOBM traffic is configured to be passive for the IGP that is utilized on that interface.
- SRG-NET-000020-RTR-000015 Medium The router must enforce information flow control using explicit security attributes on information, source, and destination objects. Security attributes used as a basis for flow control decisions may include, but are not limited to, IP addresses, port numbers, protocol, Autonomous System, and interface.
- SRG-NET-000025-RTR-000020 Medium The router must enable neighbor router authentication for control plane protocols.
- SRG-NET-000025-RTR-000085 Medium The router must be configured so that rotating keys are not used for authenticating IGP peers that have a duration exceeding 180 days.
- SRG-NET-000026-RTR-000031 Medium The router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding.
- SRG-NET-000131-RTR-000035 Medium The router must not have unnecessary services and functions enabled.
- SRG-NET-000168-RTR-000077 Medium The router must encrypt all methods of configured authentication for routing protocols.
- SRG-NET-000168-RTR-000078 Medium The router must use NIST-validated FIPS 140-2 cryptography to implement authentication encryption mechanisms for routing protocols.
- SRG-NET-000191-RTR-000081 Medium The router must ensure all eBGP routers are configured to use Generalized TTL Security Mechanism (GTSM).
- SRG-NET-000193-RTR-000111 Medium The router must manage excess bandwidth to limit the effects of packet flooding types of denial of service (DoS) attacks.
- SRG-NET-000195-RTR-000084 Medium The router must have IP source routing disabled.
- SRG-NET-000195-RTR-000086 Medium The router must restrict BGP connections to known IP addresses of neighbor routers from trusted Autonomous Systems (AS).
- SRG-NET-000205-RTR-000108 Medium The router must configure the maximum hop limit value to at least 32.
- SRG-NET-000362-RTR-000108 Medium The router must protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.
- SRG-NET-000364-RTR-000109 Medium The router must only allow incoming communications from authorized sources to be routed to authorized destinations.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000002
- Vuln IDs
-
- V-55721
- Rule IDs
-
- SV-69975r1_rule
Checks: C-56287r1_chk
Verify each router enforces approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy. If the router does not enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy, this is a finding.
Fix: F-60591r1_fix
Configure the router to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000003
- Vuln IDs
-
- V-55723
- Rule IDs
-
- SV-69977r1_rule
Checks: C-56289r1_chk
If IPv4 or IPv6 multicast routing is enabled, verify all interfaces enabled for PIM are documented in the network's multicast topology diagram. Review the router configuration to determine if multicast routing is enabled and which interfaces are enabled for PIM. If an interface is not required to support multicast routing and it is enabled, this is a finding.
Fix: F-60593r1_fix
Document all enabled interfaces for PIM in the network's multicast topology diagram. Disable support for PIM on interfaces that are not required to support it.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000004
- Vuln IDs
-
- V-55727
- Rule IDs
-
- SV-69981r1_rule
Checks: C-56293r1_chk
Review the multicast topology diagram and determine if router interfaces are enabled for IPv4 or IPv6 multicast routing. If the router is enabled for multicast routing, verify all interfaces enabled for PIM have a neighbor filter bound to the interface. The neighbor filter must only accept PIM control plane traffic from the documented PIM neighbors. If PIM neighbor filters are not bound to all interfaces that have PIM enabled, this is a finding.
Fix: F-60597r1_fix
Configure neighbor filters to only accept PIM control plane traffic from documented PIM neighbors. Bind neighbor filters to all PIM enabled interfaces.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000005
- Vuln IDs
-
- V-55729
- Rule IDs
-
- SV-69983r1_rule
Checks: C-56295r1_chk
Review the multicast topology diagram to determine if there are any documented Admin-Local (FFx4::/16), Site-Local (FFx5::/16), or Organization-Local (FFx8::/16) multicast boundaries for IPv6 traffic or any Local-Scope (239.255.0.0/16) boundaries for IPv4 traffic. Verify the appropriate boundaries are configured on the applicable multicast-enabled interfaces. If the appropriate boundaries are not configured on applicable multicast-enabled interfaces, this is a finding.
Fix: F-60599r1_fix
Configure the appropriate boundaries to contain packets addressed within the administratively scoped zone. Defined multicast addresses are FFx4::/16, FFx5::/16, FFx8::/16, and 239.255.0.0/16.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000007
- Vuln IDs
-
- V-55731
- Rule IDs
-
- SV-69985r2_rule
Checks: C-56297r2_chk
View the configuration of the router. If an interface is not being used, but is configured or enabled, this is a finding.
Fix: F-60601r2_fix
Delete inactive sub-interfaces, and disable and delete the configuration of any inactive ports on the router.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000009
- Vuln IDs
-
- V-55733
- Rule IDs
-
- SV-69987r1_rule
Checks: C-56301r1_chk
Review the configuration of each router interface connecting to an Alternate Gateway. Verify each permit statement of the ingress filter only permits packets with destination addresses of the site's NIPRNet address space or a destination address belonging to the address block assigned by the Alternate Gateway network service provider. If the ingress filter permits packets with addresses other than those specified, such as destination addresses of the site's NIPRNet address space or a destination address belonging to the address block assigned by the Alternate Gateway network service provider, this is a finding.
Fix: F-60603r1_fix
Configure the ingress filter of the perimeter router connected to an Alternate Gateway to only permit packets with destination addresses of the site's NIPRNet address space or a destination address belonging to the address block assigned by the Alternate Gateway network service provider.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000010
- Vuln IDs
-
- V-55735
- Rule IDs
-
- SV-69989r1_rule
Checks: C-56303r1_chk
Review the configuration of the router connecting to the Alternate Gateway. Verify there are no BGP neighbors configured to the remote AS that belongs to the Alternate Gateway service provider. If there are BGP neighbors connecting the remote AS of the Alternate Gateway service provider, this is a finding.
Fix: F-60607r1_fix
Configure a static route on the perimeter router to reach the AS of a router connecting to an Alternate Gateway.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000011
- Vuln IDs
-
- V-55739
- Rule IDs
-
- SV-69993r1_rule
Checks: C-56305r1_chk
Review the configuration of the route connecting to the Alternate Gateway. Verify redistribution of static routes to the Alternate Gateway is not occurring. If the static routes to the Alternate Gateway are being redistributed into an Exterior Gateway Protocol or Interior Gateway Protocol to a NIPRNet gateway, this is a finding.
Fix: F-60609r1_fix
Configure the router so that static routes are not redistributed to an Alternate Gateway into either an Exterior Gateway Protocol or Interior Gateway Protocol to the NIPRNet or to other Autonomous System.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000012
- Vuln IDs
-
- V-55741
- Rule IDs
-
- SV-69995r1_rule
Checks: C-56307r1_chk
Verify that the out-of-band management interface is an adjacency in the Interior Gateway Protocol routing domain for the management network. If the router does not enforce that Interior Gateway Protocol instances configured on the out-of-band management gateway router only peer with their own routing domain, this is a finding.
Fix: F-60613r1_fix
Configure the router to enforce that Interior Gateway Protocol instances configured on the out-of-band management gateway router only peer with their own routing domain.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000013
- Vuln IDs
-
- V-55747
- Rule IDs
-
- SV-70001r1_rule
Checks: C-56313r1_chk
Verify the Interior Gateway Protocol instance used for the managed network does not redistribute routes into the Interior Gateway Protocol instance used for the management network, and vice versa. If the Interior Gateway Protocol instance used for the managed network redistributes routes into the Interior Gateway Protocol instance used for the management network, or vice versa, this is a finding.
Fix: F-60617r1_fix
Configure the Interior Gateway Protocol instance used for the managed network to prohibit redistribution of routes into the Interior Gateway Protocol instance used for the management network, and vice versa.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-RTR-000014
- Vuln IDs
-
- V-55749
- Rule IDs
-
- SV-70003r1_rule
Checks: C-56317r1_chk
Review the configuration to verify the management interface is configured as passive for the Interior Gateway Protocol instance for the managed network. If the management interface is not configured as passive for the Interior Gateway Protocol instance for the managed network, this is a finding.
Fix: F-60621r1_fix
Configure the management interface as passive for the Interior Gateway Protocol instance configured for the managed network.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-002190
- Version
- SRG-NET-000020-RTR-000015
- Vuln IDs
-
- V-55753
- Rule IDs
-
- SV-70007r2_rule
Checks: C-56319r3_chk
If explicit security attributes (for example, IP addresses, port numbers, protocol, Autonomous System, or interface) are not used to enforce information flow control, this is a finding.
Fix: F-60623r2_fix
Configure the router to enforce organizational security policies by using explicit security attributes (for example, IP addresses, Autonomous System, or interface) on information, source, and destination objects as a basis for flow control decisions.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000025-RTR-000020
- Vuln IDs
-
- V-55757
- Rule IDs
-
- SV-70011r1_rule
Checks: C-56323r1_chk
Review the router configuration; for every protocol that affects the routing or forwarding tables (where information is exchanged between neighbors), verify that neighbor router authentication is enabled. If authentication is not enabled, this is a finding.
Fix: F-60627r1_fix
Configure authentication to be enabled for every protocol that affects the routing or forwarding tables.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000025-RTR-000085
- Vuln IDs
-
- V-55759
- Rule IDs
-
- SV-70013r1_rule
Checks: C-56325r1_chk
For each authenticated routing protocol session, review the configured key expiration dates. If any key has a lifetime of more than 180 days, this is a finding.
Fix: F-60629r2_fix
For each authenticated routing protocol session, configure each key to have a lifetime of no more than 180 days.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001094
- Version
- SRG-NET-000026-RTR-000031
- Vuln IDs
-
- V-55761
- Rule IDs
-
- SV-70015r1_rule
Checks: C-56327r2_chk
Review the router configuration to verify uRPF or an egress filter to restrict the router from accepting outbound IP packets that contain an illegitimate address in the source address field has been configured on all internal interfaces. If uRPF or an egress filter to restrict the router from accepting outbound IP packets that contain an illegitimate address in the source address field has not been configured on all internal interfaces in an enclave, this is a finding.
Fix: F-60631r1_fix
Configure the router to ensure that an egress filter or uRPF is configured to restrict the router from accepting any outbound IP packet that contains an external IP address in the source field.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-NET-000131-RTR-000035
- Vuln IDs
-
- V-55763
- Rule IDs
-
- SV-70017r1_rule
Checks: C-56329r1_chk
Review the router configuration to determine if services or functions not required for operation, or not related to router functionality (e.g., DNS, email client or server, FTP server, or web server) are enabled. If unnecessary services and functions are enabled on the router, this is a finding.
Fix: F-60633r1_fix
Remove unneeded services and functions from the router. Removal is recommended since the service or function may be inadvertently enabled otherwise. However, if removal is not possible, disable the service or function.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SRG-NET-000168-RTR-000077
- Vuln IDs
-
- V-55765
- Rule IDs
-
- SV-70019r1_rule
Checks: C-56331r1_chk
Review the router configuration; for every protocol that affects the routing or forwarding tables (where information is exchanged between neighbors), verify that neighbor router authentication is encrypting the authentication key. If authentication is not encrypting the authentication key, this is a finding.
Fix: F-60635r1_fix
Configure routing protocol authentication to encrypt the authentication key.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SRG-NET-000168-RTR-000078
- Vuln IDs
-
- V-55767
- Rule IDs
-
- SV-70021r1_rule
Checks: C-56333r2_chk
Review the router documentation to verify it is using NIST-validated FIPS 140-2 compliant cryptography for encrypted authentication mechanisms. If NIST-validated FIPS 140-2 compliant cryptography is not being used for all encrypted authentication mechanisms, this is a finding. Review the router configuration; for every protocol that affects the routing or forwarding tables (where information is exchanged between neighbors), verify that neighbor router authentication uses FIPS 140-2 validated algorithms to encrypt the authentication key. If routing protocol authentication is not using FIPS 140-2 validated algorithms to encrypt the authentication key, this is a finding.
Fix: F-60637r2_fix
Configure routing protocol authentication to use FIPS 140-2 validated algorithms and modules to encrypt the authentication key.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- SRG-NET-000191-RTR-000081
- Vuln IDs
-
- V-55769
- Rule IDs
-
- SV-70023r1_rule
Checks: C-56335r1_chk
Review the router configuration; if it is not configured to use Generalized TTL Security Mechanism (GTSM) for all Exterior Border Gateway Protocol peering sessions, this is a finding.
Fix: F-60639r1_fix
Configure all Exterior Border Gateway Protocol peering sessions to use Generalized TTL Security Mechanism (GTSM).
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- SRG-NET-000193-RTR-000111
- Vuln IDs
-
- V-55771
- Rule IDs
-
- SV-70025r1_rule
Checks: C-56337r1_chk
Review the router configuration and interview the system administrator; verify that a mechanism for traffic prioritization and bandwidth reservation exists. This arrangement must ensure that sufficient capacity is available for mission-critical traffic and enforce the traffic priorities specified by the Combatant Commanders/Services/Agencies. If no such scheme exists or it is not configured, this is a finding.
Fix: F-60641r1_fix
Implement a mechanism for traffic prioritization and bandwidth reservation. This mechanism must enforce the traffic priorities specified by the Combatant Commanders/Services/Agencies.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-002403
- Version
- SRG-NET-000195-RTR-000084
- Vuln IDs
-
- V-55773
- Rule IDs
-
- SV-70027r1_rule
Checks: C-56339r1_chk
Review the configuration to determine if source routing is enabled. If source routing is enabled, this is a finding.
Fix: F-60643r1_fix
Configure the router to disable IP source routing.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-002403
- Version
- SRG-NET-000195-RTR-000086
- Vuln IDs
-
- V-55775
- Rule IDs
-
- SV-70029r1_rule
Checks: C-56341r1_chk
Review the router configuration to verify that Border Gateway Protocol connections are only from known neighbors in a trusted AS by restricting TCP port 179 to specific IP addresses. If the router is not configured to restrict TCP port 179 to specific IP addresses, this is a finding.
Fix: F-60645r1_fix
Configure an ingress filter to block any unauthorized BGP connection attempts by restricting TCP port 179 to specific IP addresses (authorized BGP peers).
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001097
- Version
- SRG-NET-000205-RTR-000108
- Vuln IDs
-
- V-55777
- Rule IDs
-
- SV-70031r1_rule
Checks: C-56343r1_chk
Review the router configuration to determine if the maximum hop limit has been configured. If it has been configured, then it must be set to at least 32. If it has not been configured, it must be determined what the default value is. If the default value is below 32 and the maximum hop limit value has not been configured (set to at least 32), this is a finding. In any case, maximum hop limit must be at least 32.
Fix: F-60647r1_fix
Configure the router maximum hop limit value to at least 32.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- SRG-NET-000235-RTR-000114
- Vuln IDs
-
- V-55779
- Rule IDs
-
- SV-70033r1_rule
Checks: C-56345r1_chk
Verify the router stops forwarding traffic or maintains the configured security policies upon the failure of the following actions: system initialization, shutdown, or system abort. If the router does not stop forwarding traffic or maintain the configured security policies upon the failure of the following actions: system initialization, shutdown, or system abort, this is a finding.
Fix: F-60649r1_fix
Configure the router to stop forwarding traffic or maintain the configured security policies upon the failure of the following actions: system initialization, shutdown, or system abort.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- SRG-NET-000362-RTR-000110
- Vuln IDs
-
- V-55781
- Rule IDs
-
- SV-70035r1_rule
Checks: C-56347r1_chk
Determine whether control plane protection has been implemented on the device by verifying traffic types have been classified based on importance levels and a policy has been configured to filter and rate limit the traffic according to each class. If the router does not have control plane protection implemented, this is a finding.
Fix: F-60651r1_fix
Implement control plane protection by classifying traffic types based on importance and configure filters to restrict and rate limit the traffic directed to and processed by the route processor according to each class.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-002403
- Version
- SRG-NET-000364-RTR-000109
- Vuln IDs
-
- V-55785
- Rule IDs
-
- SV-70039r1_rule
Checks: C-56355r2_chk
Review the router configuration to determine if the router only allows incoming communications from authorized sources to be routed to authorized destinations. If the router does not restrict incoming communications to allow only authorized sources and destinations, this is a finding.
Fix: F-60659r1_fix
Configure the router to only allow incoming communications from authorized sources to be routed to authorized destinations.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001126
- Version
- SRG-NET-000365-RTR-000112
- Vuln IDs
-
- V-55789
- Rule IDs
-
- SV-70043r1_rule
Checks: C-56357r1_chk
Review the documentation of the router or interview the System Administrator. Verify that the router fails securely in the event of an operational failure. If it cannot, this is a finding.
Fix: F-60661r1_fix
This is a capability that would be intrinsic to the router as a result of its development and may not be configurable. If it is a configurable option, configure the device to fail securely in the event of an operational failure.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-RTR-000113
- Vuln IDs
-
- V-55791
- Rule IDs
-
- SV-70045r1_rule
Checks: C-56359r1_chk
Review the configuration of the router and verify that it is configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance. This may involve interviewing the System Administrators, ISSM or personnel designated by the ISSM, and the program's Configuration Management personnel. If it is not configured in accordance with DoD security configuration or implementation guidance, this is a finding.
Fix: F-60663r1_fix
Configure the router in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including NSA configuration guides, CTOs, and DTMs. Follow local change management processes when implementing configuration changes.