1.31 CISC-RT-000500

Information

The Cisco BGP switch must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).

GROUP ID: V-221104
RULE ID: SV-221104r999713

Accepting route advertisements belonging to the local AS can result in traffic looping or being black-holed, or at a minimum, using a non-optimized path.

Solution

Configure the switch to reject inbound route advertisements for any prefixes belonging to the local AS.

Step 1 : Add to the prefix filter list those prefixes belonging to the local autonomous system.

SW1(config)# ip prefix-list PREFIX_FILTER seq 74 deny x.13.1.0/24 le 32

Step 2 : If not already completed to be compliant with previous requirement, apply the prefix list filter inbound to each external BGP neighbor as shown in the example below:

SW1(config)# router bgp xx
SW1(config-router)# neighbor x.1.12.2
SW1(config-router-neighbor)# address-family ipv4 unicast
SW1(config-router-neighbor-af)# prefix-list PREFIX_FILTER in
SW1(config-router-neighbor-af)# exit
SW1(config-router-neighbor)# exit
SW1(config-router)# neighbor x.2.44.4
SW1(config-router-neighbor)# address-family ipv4 unicast
SW1(config-router-neighbor-af)# prefix-list PREFIX_FILTER in
SW1(config-router-neighbor-af)# end

See Also

https://workbench.cisecurity.org/benchmarks/26426

Item Details

Category: ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-4, 800-53|CA-7, 800-53|SC-4, CCI|CCI-001368, CSCv7|13.3, Rule-ID|SV-221104r999713_rule, STIG-ID|CISC-RT-000500, Vuln-ID|V-221104

Plugin: Cisco

Control ID: 88b7067f14ff6e88b09d2cd4fb8d78d8b979d606bcf8291bb8b61022401d2b8e