BGP: Disable Capability Negotiation

Information

This command disables the exchange of capabilities. When command is enabled and after the peering is flapped, any new capabilities are not negotiated and will strictly support IPv4 routing exchanges with that peer. The no form of the command removes this command from the configuration and restores the normal behavior. This is beneficial in Internet peering environment when only address-family exchanged is IPv4.

NOTE: Nessus has determined that BGP is disabled.

Solution

Run the following command on the device to disable capability negotiation: configure router bgp group <group-id> disable-capability-negotiation

See Also

https://infoproducts.alcatel-lucent.com/aces/cgi-bin/dbaccessfilename.cgi/9305050101_V1_SR-OS Security Best Practices v2.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7c.

Plugin: Alcatel

Control ID: 102e17f075bf81028f3adf3dead32b01312ea954f679533499db05aaf75290bd