STIGQter STIGQter: STIG Summary: SDN Using NV Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 Feb 2017:

SDN-enabled routers and switches must rate limit the amount of unknown data plane packets that are punted to the SDN controller.

DISA Rule

SV-87753r1_rule

Vulnerability Number

V-73101

Group Title

NET-SDN-015

Rule Version

NET-SDN-015

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the SDN manager or controller to set a threshold on the number of unknown data plane packets that are allowed to be punted by a virtual router or switch to the controller within a specific amount of time.

Configure all physical SDN-enabled switches and routers to rate limit the amount of packets that are punted to the SDN controller.

Check Contents

Review the parameters provided by the SDN manager or controller when deploying router or switch instances to determine if they set a threshold on the number of unknown data plane packets that are allowed to be punted by a virtual router or switch to the controller within a specific amount of time.

Review the configuration of all physical SDN-enabled switches and routers and verify that packet-in messages are rate limited.

If SDN-enabled routers and switches do not rate limit the amount of unknown data plane packets that are punted to the SDN controller, this is a finding.

Vulnerability Number

V-73101

Documentable

False

Rule Version

NET-SDN-015

Severity Override Guidance

Review the parameters provided by the SDN manager or controller when deploying router or switch instances to determine if they set a threshold on the number of unknown data plane packets that are allowed to be punted by a virtual router or switch to the controller within a specific amount of time.

Review the configuration of all physical SDN-enabled switches and routers and verify that packet-in messages are rate limited.

If SDN-enabled routers and switches do not rate limit the amount of unknown data plane packets that are punted to the SDN controller, this is a finding.

Check Content Reference

M

Target Key

3089

Comments