3.8 Ensure Loopback interface address is set

Information

Configure a Loopback address.

Rationale:

When a router needs to initiate connections to remote hosts, for example for SYSLOG or NTP, it will use the nearest interface for the packets source address. This can cause issues due to the possible variation in source, potentially causing packets to be denied by intervening firewalls or handled incorrectly by the receiving host.

To prevent these problems the router should be configured with a Loopback interface and any services should be bound to this address.

Solution

To create a loopback interface enter the following command from the [edit interfaces] hierarchy:

[edit interfaces]
user@host#set lo0 unit 0 family inet address <ip address>

Default Value:

No Loopback Address is configured by default.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|11

Plugin: Juniper

Control ID: 289997c905abd24f7e9f4602906a77701ef9824c2516d4779bdbd7bde5ab105d