CISC-RT-000490 - The Cisco BGP switch must be configured to reject inbound route advertisements for any Bogon prefixes.

Information

Accepting route advertisements for Bogon prefixes can result in the local autonomous system (AS) becoming a transit for malicious traffic as it will in turn advertise these prefixes to neighbor autonomous systems.

Solution

Configure the switch to reject inbound route advertisements for any Bogon prefixes.

Step 1: Configure a prefix list containing the current Bogon prefixes as shown below:

SW1(config)#ip prefix-list PREFIX_FILTER deny 0.0.0.0/8 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 10.0.0.0/8 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 100.64.0.0/10 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 127.0.0.0/8 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 169.254.0.0/16 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 172.16.0.0/12 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 192.0.2.0/24 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 192.88.99.0/24 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 192.168.0.0/16 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 198.18.0.0/15 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 198.51.100.0/24 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 203.0.113.0/24 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 224.0.0.0/4 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 240.0.0.0/4 le 32
SW1(config)#ip prefix-list PREFIX_FILTER deny 240.0.0.0/4 le 32
SW1(config)#ip prefix-list PREFIX_FILTER permit 0.0.0.0/0 ge 8

Step 2: Apply the prefix list filter inbound to each external BGP neighbor as shown in the example:

SW1(config)#router bgp xx
SW1(config-switch)#neighbor x.1.1.9 prefix-list PREFIX_FILTER in
SW1(config-switch)#neighbor x.2.1.7 prefix-list PREFIX_FILTER in

Route Map Alternative:

Step 1: Configure the route map referencing the configured prefix list above.

SW1(config)#route-map FILTER_PREFIX_MAP 10
SW1(config-route-map)#match ip address prefix-list PREFIX_FILTER
SW1(config-route-map)#exit

Step 2: Apply the route-map inbound to each external BGP neighbor as shown in the example:

SW1(config)#router bgp xx
SW1(config-switch)#neighbor x.1.1.9 route-map FILTER_PREFIX_MAP in
SW1(config-switch)#neighbor x.2.1.7 route-map FILTER_PREFIX_MAP in
SW1(config-switch)#end

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cisco_IOS-XE_Switch_Y23M10_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4, CAT|II, CCI|CCI-001368, Rule-ID|SV-221023r622190_rule, STIG-ID|CISC-RT-000490, STIG-Legacy|SV-110867, STIG-Legacy|V-101763, Vuln-ID|V-221023

Plugin: Cisco

Control ID: 37ec367c141d6dfe086249a5114c68f3832fcb33bcf10a7e92e05932b248224f