NET-TUNL-012 - Tunnel Default Router Configured

Information

Default routes must not be directed to the tunnel entry point.

Routing in the network containing the tunnel entry point must be configured to direct the intended traffic into the tunnel. Depending on the router products used this may be done by creating routes to a tunnel by name, by address, or by interface.

If multiple tunnels are defined or IPv6 interfaces, you must be selective with static routes, policy based routing, or even let the interior gateway protocol (IGP) make the decision since a ipv4 or ipv6 address has been configured on the tunnel. The key is the administrator should carefully plan and configure or let the IGP determine what goes into each tunnel.

NOTE: This check requires manual verification to identify the tunnel endpoints, then review all routing devices to ensure the tunnel entry point is not used as a default route.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

The SA must carefully plan and configure or let IGP determine what goes into each tunnel.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-20504r2_rule, STIG-ID|NET-TUNL-012, Vuln-ID|V-18790

Plugin: Cisco

Control ID: 13eaa8537846ec94066a7b444d3a3514dabd6cf765073f03bc0b57f9184ad5df