JUEX-RT-000750 - The Juniper perimeter router must be configured to have Link Layer Discovery Protocols (LLDPs) disabled on all external interfaces.

Information

LLDPs are primarily used to obtain protocol addresses of neighboring devices and discover platform capabilities of those devices. Use of SNMP with the LLDP Management Information Base (MIB) allows network management applications to learn the device type and the SNMP agent address of neighboring devices, thereby enabling the application to send SNMP queries to those devices. LLDPs are also media- and protocol-independent as they run over the data link layer; therefore, two systems that support different network-layer protocols can still learn about each other. Allowing LLDP messages to reach external network nodes is dangerous as it provides an attacker a method to obtain information of the network infrastructure that can be useful to plan an attack.

Solution

This requirement is not applicable for the DODIN Backbone.

Disable LLDPs on all external interfaces.

set protocols lldp interface all disable
set protocols lldp interface <interior interface>
set protocols lldp interface <exterior interface> disable

set protocols lldp-med interface all disable
set protocols lldp-med interface <interior interface>
set protocols lldp-med interface <exterior interface> disable

Note: The <exterior interface> disable command is not required if LLDP and LLDP-MED are globally disabled. However, the configured protocol status may be more apparent if each exterior interface is explicitly disabled.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_EX_Switches_Y23M07_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11), CAT|III, CCI|CCI-002403, Rule-ID|SV-254047r844174_rule, STIG-ID|JUEX-RT-000750, Vuln-ID|V-254047

Plugin: Juniper

Control ID: ab58432063f7fb080ffd3bd166d66c80a6d6ed14c1e4ebfbfa327c8f4d1521d8