1.34 CISC-RT-000530

Information

The Cisco BGP switch must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.

GROUP ID: V-221107
RULE ID: SV-221107r999716

Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a non-optimized path.

Solution

Step 1 : Configure a prefix list for containing all customer and local AS prefixes as shown in the example below:

SW1(config)# ip prefix-list FILTER_CORE_PREFIXES deny x.1.1.0/24 le 32
SW1(config)# ip prefix-list FILTER _CORE_PREFIXES deny x.1.2.0/24 le 32
SW1(config)# ip prefix-list FILTER _CORE_PREFIXES permit 0.0.0.0/0 ge 8

Step 2 : Apply the prefix list filter outbound to each CE neighbor as shown in the example below:

SW1(config)# router bgp xx
SW1(config-router)# neighbor x.1.12.2
SW1(config-router-neighbor)# address-family ipv4 unicast
SW1(config-router-neighbor-af)# prefix-list FILTER _CORE_PREFIXES out
SW1(config-router-neighbor-af)# exit
SW1(config-router-neighbor)# exit
SW1(config-router)# neighbor x.2.44.4
SW1(config-router-neighbor)# address-family ipv4 unicast
SW1(config-router-neighbor-af)# prefix-list FILTER _CORE_PREFIXES out
SW1(config-router-neighbor-af)# end

See Also

https://workbench.cisecurity.org/benchmarks/26426

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-7, 800-53|SC-4, 800-53|SC-7a., CCI|CCI-001097, CSCv7|13.3, Rule-ID|SV-221107r999716_rule, STIG-ID|CISC-RT-000530, Vuln-ID|V-221107

Plugin: Cisco

Control ID: 312fdf70215206ce71d4d35a8c40a06becff236577255e1677e662e9db53da47