CISC-RT-000530 - The Cisco BGP switch must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.

Information

Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a nonoptimized path.

Solution

Step 1: Configure a prefix list for containing all customer and local AS prefixes as shown in the example below:

R1(config)#ip prefix-list FILTER_CORE_PREFIXES deny x.1.1.0/24 le 32
R1(config)#ip prefix-list FILTER _CORE_PREFIXES deny x.1.2.0/24 le 32
R1(config)#ip prefix-list FILTER _CORE_PREFIXES permit 0.0.0.0/0 ge 8

Step 2: Apply the prefix list filter outbound to each CE neighbor as shown in the example.

router bgp xx
address-family ipv4
neighbor x.1.4.12 prefix-list FILTER _CORE_PREFIXES out

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cisco_IOS-XE_Switch_Y23M10_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7a., CAT|II, CCI|CCI-001097, Rule-ID|SV-221027r929070_rule, STIG-ID|CISC-RT-000530, STIG-Legacy|SV-110875, STIG-Legacy|V-101771, Vuln-ID|V-221027

Plugin: Cisco

Control ID: 596b3ed3e31e8dcdbc81f581602441768cab12b837beaea28358f50757192034