3.1.4 Set 'ip verify unicast source reachable-via'

Information

Examines incoming packets to determine whether the source address is in the Forwarding Information Base (FIB) and permits the packet only if the source is reachable through the interface on which the packet was received (sometimes referred to as strict mode).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure uRPF.
hostname(config)#interface {interface_name}
hostname(config-if)#ip verify unicast source reachable-via rx

See Also

https://workbench.cisecurity.org/files/508

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(16)

Plugin: Cisco

Control ID: 66630f15e619a25720ed7428e6e477737383d1e031b0a0d33d933fde40f1975a