AMLS-L3-000290 - The Arista Multilayer Switch must configure the maximum hop limit value to at least 32.

Information

The Neighbor Discovery protocol allows a hop limit value to be advertised by routers in a Router Advertisement message to be used by hosts instead of the standardized default value. If a very small value was configured and advertised to hosts on the LAN segment, communications would fail due to the hop limit reaching zero before the packets sent by a host reached their destination.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the router maximum hop limit value to at least 32.

From the interface configuration mode, enter:

ipv6 nd ra hop-limit 32

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Arista_MLS_DCS-7000_Series_Y20M07_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7a., CAT|II, CCI|CCI-001097, Group-ID|V-60927, Rule-ID|SV-75385r2_rule, STIG-ID|AMLS-L3-000290, Vuln-ID|V-60927

Plugin: Arista

Control ID: 3b1602e34c718b9280a2d450e9a85ce7014cb2f289ab2d0b77403dfba08b4acf