SV-207100r604135_rule
V-207100
SRG-NET-000018
SRG-NET-000018-RTR-000004
CAT II
10
Configure all eBGP routers to reject inbound route advertisements from a CE router for prefixes that are not allocated to that customer.
Review the router configuration to verify that there are filters defined to only accept routes for prefixes that belong to specific customers.
The prefix filter must be referenced inbound on the appropriate BGP neighbor statement.
If the router is not configured to reject inbound route advertisements from each CE router for prefixes that are not allocated to that customer, this is a finding.
Note: Routes to PE-CE links within a VPN are needed for troubleshooting end-to-end connectivity across the MPLS/IP backbone. Hence, these prefixes are an exception to this requirement.
V-207100
False
SRG-NET-000018-RTR-000004
Review the router configuration to verify that there are filters defined to only accept routes for prefixes that belong to specific customers.
The prefix filter must be referenced inbound on the appropriate BGP neighbor statement.
If the router is not configured to reject inbound route advertisements from each CE router for prefixes that are not allocated to that customer, this is a finding.
Note: Routes to PE-CE links within a VPN are needed for troubleshooting end-to-end connectivity across the MPLS/IP backbone. Hence, these prefixes are an exception to this requirement.
M
2917