SV-221139r622190_rule
V-221139
SRG-NET-000364-RTR-000115
CISC-RT-000870
CAT II
10
Step 1: Configure the report policy to filter IGMP Membership Report messages as shown in the example below:
SW1(config-route-map)# route-map ALLOWED_SOURCES permit 10
SW1(config-route-map)# match ip multicast source x.1.2.6/32
SW1(config-route-map)# route-map ALLOWED_SOURCES permit 20
SW1(config-route-map)# match ip multicast source x.1.2.7/32
SW1(config-route-map)# route-map ALLOWED_SOURCES deny 30
SW1(config-route-map)# match ip multicast source 0.0.0.0/0
SW1(config-route-map)# exit
Step 2: Apply the report policy to all applicable interfaces.
SW1(config)# int e2/4
SW1(config-if)# ip igmp report-policy ALLOWED_SOURCES
SW1(config-if)# end
Review the configuration of the DR to verify that it is filtering IGMP or MLD report messages, allowing hosts to only join multicast groups from sources that have been approved.
Step 1: Verify that all host-facing interfaces are configured to filter IGMP Membership Report messages (IGMP joins) as shown in the example below:
interface Ethernet2/4
no switchport
ip address 10.2.22.3/24
ip pim sparse-mode
ip igmp version 3
ip igmp report-policy ALLOWED_SOURCES
Step 2: Verify that the report policy permits only sources that have been approved by the organization.
route-map ALLOWED_SOURCES permit 10
match ip multicast source x.1.2.6/32
route-map ALLOWED_SOURCES permit 20
match ip multicast source x.1.2.7/32
route-map ALLOWED_SOURCES deny 30
match ip multicast source 0.0.0.0/0
Note: This requirement is only applicable to Source Specific Multicast (SSM) implementation.
If the DR is not filtering IGMP or MLD report messages, this is a finding.
V-221139
False
CISC-RT-000870
Review the configuration of the DR to verify that it is filtering IGMP or MLD report messages, allowing hosts to only join multicast groups from sources that have been approved.
Step 1: Verify that all host-facing interfaces are configured to filter IGMP Membership Report messages (IGMP joins) as shown in the example below:
interface Ethernet2/4
no switchport
ip address 10.2.22.3/24
ip pim sparse-mode
ip igmp version 3
ip igmp report-policy ALLOWED_SOURCES
Step 2: Verify that the report policy permits only sources that have been approved by the organization.
route-map ALLOWED_SOURCES permit 10
match ip multicast source x.1.2.6/32
route-map ALLOWED_SOURCES permit 20
match ip multicast source x.1.2.7/32
route-map ALLOWED_SOURCES deny 30
match ip multicast source 0.0.0.0/0
Note: This requirement is only applicable to Source Specific Multicast (SSM) implementation.
If the DR is not filtering IGMP or MLD report messages, this is a finding.
M
4075