STIGQter STIGQter: STIG Summary: Router Security Requirements Guide Version: 4 Release: 2 Benchmark Date: 23 Apr 2021:

The router must be configured to log all packets that have been dropped.

DISA Rule

SV-207122r604135_rule

Vulnerability Number

V-207122

Group Title

SRG-NET-000078

Rule Version

SRG-NET-000078-RTR-000001

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure interface ACLs to log all deny statements.

Check Contents

Review the router interface access control lists (ACLs) to verify all deny statements are logged.

If packets being dropped are not logged, this is a finding.

Vulnerability Number

V-207122

Documentable

False

Rule Version

SRG-NET-000078-RTR-000001

Severity Override Guidance

Review the router interface access control lists (ACLs) to verify all deny statements are logged.

If packets being dropped are not logged, this is a finding.

Check Content Reference

M

Target Key

2917

Comments