SV-207144r604135_rule
V-207144
SRG-NET-000205
SRG-NET-000205-RTR-000012
CAT II
10
If the management interface is a routed interface, it must be configured with both an ingress and egress ACL.
Step 1: Verify that the managed interface has an inbound and outbound ACL configured.
Step 2: Verify that the ingress filter only allows management, IGP, and ICMP traffic.
Caveat: If the management interface is a true OOBM interface, this requirement is not applicable.
If the router does not restrict traffic that ingresses and egresses the management interface, this is a finding.
V-207144
False
SRG-NET-000205-RTR-000012
Step 1: Verify that the managed interface has an inbound and outbound ACL configured.
Step 2: Verify that the ingress filter only allows management, IGP, and ICMP traffic.
Caveat: If the management interface is a true OOBM interface, this requirement is not applicable.
If the router does not restrict traffic that ingresses and egresses the management interface, this is a finding.
M
2917