DISA STIG Cisco NX-OS Switch RTR v2r1

Audit Details

Name: DISA STIG Cisco NX-OS Switch RTR v2r1

Updated: 4/25/2022

Authority: DISA STIG

Plugin: Cisco

Revision: 1.4

Estimated Item Count: 152

File Details

Filename: DISA_STIG_Cisco_NX-OS_Switch_RTR_v2r1.audit

Size: 707 kB

MD5: 6cdad0e95b0d789d5e6b1bb054b6b4e6
SHA256: 1c8876af4b3a1f6a285cc4c04200c5db56deb728a2327396dc56f462fdeefb8e

Audit Changelog

 
Revision 1.4

Apr 25, 2022

Functional Update
  • CISC-RT-000600 - The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange - isis
  • CISC-RT-000610 - The MPLS switch with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core switches.
Revision 1.3

Apr 5, 2022

Functional Update
  • CISC-RT-000600 - The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange - isis
  • CISC-RT-000610 - The MPLS switch with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core switches.
Miscellaneous
  • Metadata updated.
  • References updated.
  • See also link updated.
Added
  • CISC-RT-000236 - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.
  • CISC-RT-000237 - The Cisco switch must not be configured to use IPv6 Site Local Unicast addresses.
  • CISC-RT-000391 - The Cisco perimeter switch must be configured to suppress Router Advertisements on all external IPv6-enabled interfaces.
Revision 1.2

Jul 30, 2021

Functional Update
  • CISC-RT-000600 - The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange - isis
  • CISC-RT-000610 - The MPLS switch with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core switches.
Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.1

Jun 17, 2021

Functional Update
  • CISC-RT-000600 - The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange - isis
  • CISC-RT-000610 - The MPLS switch with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core switches.
Miscellaneous
  • Metadata updated.