SV-207139r604135_rule
V-207139
SRG-NET-000205
SRG-NET-000205-RTR-000007
CAT I
10
Configure protection for the IP core to be implemented at the edges by blocking any traffic with a destination address assigned to the IP core infrastructure.
Review the router configuration to verify that an ingress ACL is applied to all CE-facing interfaces.
Verify that the ingress ACL rejects and logs packets destined to the IP core address block.
If the PE router is not configured to block any traffic with a destination address assigned to the IP core infrastructure, this is a finding.
Note: Internet Control Message Protocol (ICMP) echo requests and traceroutes will be allowed to the edge from external adjacent peers.
V-207139
False
SRG-NET-000205-RTR-000007
Review the router configuration to verify that an ingress ACL is applied to all CE-facing interfaces.
Verify that the ingress ACL rejects and logs packets destined to the IP core address block.
If the PE router is not configured to block any traffic with a destination address assigned to the IP core infrastructure, this is a finding.
Note: Internet Control Message Protocol (ICMP) echo requests and traceroutes will be allowed to the edge from external adjacent peers.
M
2917