SV-216566r531085_rule
V-216566
SRG-NET-000362-RTR-000114
CISC-RT-000180
CAT II
10
Disable ip mask-reply on all external interfaces as shown below.
R4(config)#int g0/1
R4(config-if)#no ip mask-reply
Review the router configuration and verify that ip mask-reply command is not enabled on any external interfaces as shown in the example below.
interface GigabitEthernet0/1
ip address x.x.x.x 255.255.255.0
ip mask-reply
If the ip mask-reply command is configured on any external interface, this is a finding.
V-216566
False
CISC-RT-000180
Review the router configuration and verify that ip mask-reply command is not enabled on any external interfaces as shown in the example below.
interface GigabitEthernet0/1
ip address x.x.x.x 255.255.255.0
ip mask-reply
If the ip mask-reply command is configured on any external interface, this is a finding.
M
4027