Ensure 'EIGRP authentication' is enabled

Information

Enables the authentication of EIGRP neighbor before routing information is received from the neighbor

Rationale:

Enabling the routing protocol authentication prevents against attackers who can send wrong routing information in order to redirect traffic to their network or send malformed packets in order to saturate and to exhaust the control plane.

Solution

Predefined FlexConfig object found in Firepower Management Center:

FlexConfig Object Name - Eigrp_Configure
Configures EIGRP routing next-hop, auto-summary, router-id, eigrp-stub.

See Also

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/hardening/ftd/FTD_Hardening_Guide_v64.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Cisco_Firepower

Control ID: 96f16484bf51702181c33a69cb62d5a6eaf4229a702c27da969bc353b22a5edf