SV-221117r622190_rule
V-221117
SRG-NET-000512-RTR-000005
CISC-RT-000630
CAT I
10
Configure the PE switch to have each VRF bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.
Step 1: Review the design plan for deploying MPLS/L3VPN.
Step 2: Review all CE-facing interfaces and verify that the proper VRF is defined via the ip vrf forwarding command. In the example below, customer 1 is bound to interface Ethernet2/1, while customer 2 is bound to Ethernet2/2.
interface Ethernet2/1
no switchport
vrf member CUST1
ip address x.2.22.3/24
interface Ethernet2/2
no switchport
vrf member CUST2
ip address x.2.8.4/24
If any VRFs are not bound to the appropriate physical or logical interface, this is a finding.
V-221117
False
CISC-RT-000630
Step 1: Review the design plan for deploying MPLS/L3VPN.
Step 2: Review all CE-facing interfaces and verify that the proper VRF is defined via the ip vrf forwarding command. In the example below, customer 1 is bound to interface Ethernet2/1, while customer 2 is bound to Ethernet2/2.
interface Ethernet2/1
no switchport
vrf member CUST1
ip address x.2.22.3/24
interface Ethernet2/2
no switchport
vrf member CUST2
ip address x.2.8.4/24
If any VRFs are not bound to the appropriate physical or logical interface, this is a finding.
M
4075