SV-221001r622190_rule
V-221001
SRG-NET-000362-RTR-000114
CISC-RT-000180
CAT II
10
Disable ip mask-reply on all external interfaces as shown below:
SW1(config)#int g0/1
SW1(config-if)#no ip mask-reply
Review the switch configuration and verify that ip mask-reply command is not enabled on any external interfaces as shown in the example below:
interface GigabitEthernet0/1
ip address x.x.x.x 255.255.255.0
ip mask-reply
If the ip mask-reply command is configured on any external interface, this is a finding.
V-221001
False
CISC-RT-000180
Review the switch configuration and verify that ip mask-reply command is not enabled on any external interfaces as shown in the example below:
interface GigabitEthernet0/1
ip address x.x.x.x 255.255.255.0
ip mask-reply
If the ip mask-reply command is configured on any external interface, this is a finding.
M
4074