NET0166 - AG Network IP addresses are advertised in enclave - 'EIGRP distribute lists prefix lists'

Information

The IAO/NSO will ensure the AG network service provider IP addresses are not redistributed into or advertised to the NIPRNet or any router belonging to any other Autonomous System (AS) i.e. to another AG device in another AS.

Unsolicited traffic that may inadvertently attempt to enter the NIPRNet by traversing the enclave's premise router can be avoided by not redistributing NIPRNet routes into the AG.

NOTE: This check only looks for the presence of a distribution list for the given routing protocol. You will need to manually verify that the referenced list contains the proper route filters for your organization.
NOTE: Change 'AG_INTERFACE_NAME' to the interface address that connects to the approved gateway service provider if configured.

Solution

Use distribute lists prefix lists to insure AG routes are not redistributed into the NIPRNet BGP or sites IGP (OSPF, EIGRP, RIP, etc).

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(21), CAT|III, Rule-ID|SV-4624r2_rule, STIG-ID|NET0166, Vuln-ID|V-4624

Plugin: Cisco

Control ID: 58decd7755fe1bc9a518e3fa0ef8972cbf210570deb65e306f7f20de9eb9bb77