NET-MCAST-002 - PIM neighbor filter is not configured - 'ip pim neighbor-filter IP_PIM_NEIGHBORS_ACL'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The administrator must ensure that a PIM neighbor filter is bound to all interfaces that have PIM enabled.

Protocol Independent Multicast (PIM) is a routing protocol used to build multicast distribution tress for forwarding multicast traffic across the network infrastructure. PIM traffic must be limited to only known PIM neighbors by configuring and binding a PIM neighbor filter to those interfaces that have PIM enabled.

NOTE: This check may need to be duplicated if there are multiple PIM enabled interfaces.
NOTE: Change 'PIM_INTERFACE' to the IP interface with PIM enabled.
NOTE: Change 'IP_PIM_NEIGHBORS_ACL' to the standard access-list used for filtering authorized PIM neighbors.

Solution

If IPv4 or IPv6 multicast routing is enabled, ensure that all interfaces enabled for PIM has a neighbor filter to only accept PIM control plane traffic from the documented routers according to the multicast topology diagram.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11), CAT|II, Rule-ID|SV-40315r1_rule, STIG-ID|NET-MCAST-002, Vuln-ID|V-30578

Plugin: Cisco

Control ID: b6b538d9a53f28bb54ef81cd0b5a362bd2d6db2e54fe7e0ddc85772a2c7f5c08