1.1.2 Control Plane ACL

Information

A default control plane ACL is provided and applied to the system control-plane. The default control-place ACL is read-only, but you can create and assign a different ACL to the system control-plane if customization is needed. However, it is strongly recommended to use the default control-plane ACL as a template for any custom ACL that you may apply to ensure protocol and management operations function correctly.

The default control plane ACL filters all IP traffic inbound and outbound on any management interface. SSH, Telnet, NTP, SNMP, IP protocols, and logging/matching on management traffic are done by this ACL. The default control plane ACL permits the following protocols:

- Telnet
- SSH
- HTTP/S
- BootP
- SNMP
- ICMP
- MLAG
- IGMP
- OSPF
- BGP
- VRRP
- PIM
- AHP
- VNC

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Apply a control plane ACL to the default vrf and all non default vrfs

switch(config)#system control-plane
switch(config-system-cp)# ip access-group custom-control-plane-acl in
switch(config-system-cp)# ip access-group custom-control-plane-acl vrf MGMT in

Impact:

While it is possible to create and apply a new/modified ACL to the system control-plane, modifying the control plane ACL may unexpectedly block services critical to the network operation. The default control plane allows all expected control plane protocols. A custom control plane acl may be overly broad, providing insufficient security, or too narrow to allow the network to function.

See Also

https://workbench.cisecurity.org/benchmarks/25683

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(15)

Plugin: Arista

Control ID: 32ae9c4062ebfd06e03734c76fa2b13af3fa6040f441d91558203d8c34e72a92