SV-216761r531087_rule
V-216761
SRG-NET-000205-RTR-000004
CISC-RT-000330
CAT II
10
This requirement is not applicable for the DODIN Backbone.
Configure the router to use an inbound ACL on all external interfaces as shown in the example below.
RP/0/0/CPU0:R3(config)#int g0/0/0/1
RP/0/0/CPU0:R3(config-if)#ipv4 access-group EXTERNAL_ACL_INBOUND in
RP/0/0/CPU0:R3(config-if)#end
This requirement is not applicable for the DODIN Backbone.
Review the router configuration to verify that an inbound ACL is configured on all external interfaces as shown in the example below.
interface GigabitEthernet0/0/0/1
ipv4 address x.11.1.2 255.255.255.252
ipv4 access-group EXTERNAL_ACL_INBOUND ingress
If the router is not configured to filter traffic entering the network at all external interfaces in an inbound direction, this is a finding.
V-216761
False
CISC-RT-000330
This requirement is not applicable for the DODIN Backbone.
Review the router configuration to verify that an inbound ACL is configured on all external interfaces as shown in the example below.
interface GigabitEthernet0/0/0/1
ipv4 address x.11.1.2 255.255.255.252
ipv4 access-group EXTERNAL_ACL_INBOUND ingress
If the router is not configured to filter traffic entering the network at all external interfaces in an inbound direction, this is a finding.
M
4029