SV-221084r622190_rule
V-221084
SRG-NET-000362-RTR-000113
CISC-RT-000170
CAT II
10
Disable ip unreachables on all external interfaces as shown below:
SW1(config)# int e2/7
SW1(config-if)# no ip unreachables
SW1(config-if)# end
Review the switch configuration to determine if it is compliant with this requirement. The ip unreachables command must not be found on any interface as shown in the example below:
interface Ethernet2/7
no switchport
ip address x.22.4.2/30
ip unreachables
If ICMP unreachable notifications are sent from any external interfaces, this is a finding.
V-221084
False
CISC-RT-000170
Review the switch configuration to determine if it is compliant with this requirement. The ip unreachables command must not be found on any interface as shown in the example below:
interface Ethernet2/7
no switchport
ip address x.22.4.2/30
ip unreachables
If ICMP unreachable notifications are sent from any external interfaces, this is a finding.
M
4075