SV-216747r531087_rule
V-216747
SRG-NET-000362-RTR-000114
CISC-RT-000180
CAT II
10
Disable ipv4 mask-reply on all external interfaces as shown below.
RP/0/0/CPU0:R3(config)#int g0/0/0/1
RP/0/0/CPU0:R3(config-if)#no ipv4 mask-reply
Review the router configuration and verify that ipv4 mask-reply command is not enabled on any external interfaces as shown in the example below.
interface GigabitEthernet0/0/0/1
ipv4 address x.11.1.2 255.255.255.252
ipv4 mask-reply
If the router configuration has the ipv4 mask-reply command is enabled on any external interfaces, this is a finding.
V-216747
False
CISC-RT-000180
Review the router configuration and verify that ipv4 mask-reply command is not enabled on any external interfaces as shown in the example below.
interface GigabitEthernet0/0/0/1
ipv4 address x.11.1.2 255.255.255.252
ipv4 mask-reply
If the router configuration has the ipv4 mask-reply command is enabled on any external interfaces, this is a finding.
M
4029