3.1.3.3 Log OSPF Adjacency Changes

Information

Logging changes to the BGP peering relationships is recommended.

Rationale:

Any logged changes in a routing peer relationship will in the best case indicate a service issue due to standard operational issues (connectivity issues and so on) or in the worst case, could indicate malicious activity attempting to subvert the peering relationship and/or the routing table.

Impact:

Errors on adjacency relationships are a common early warning message in attacks on routers. If successful, a malicious actor can advertise bogus routes to valid hosts or networks, allowing the interception and modification of traffic intended for those hosts or subnets.

For this reason it is important that OSPF endpoints alert on any interruptions in adjacency.

Solution

Enabling the logging of adjacencies is a single line in the OSPF process section. It is globally applied to all OSPF neighbors.

switch(config)# router ospf <Process tag>
switch(config-router)# log-adjacency-changes

Default Value:

By default changes in OSPF adjacencies are not logged.

See Also

https://workbench.cisecurity.org/files/3102

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|11

Plugin: Cisco

Control ID: 15646cf97990dc81339779f17864c341907c728ca3e4f6f53bb9e7e66e87f187