NET-TUNL-012 - Default routes must not be directed to the tunnel entry point.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Routing in the network containing the tunnel entry point must be configured to direct the intended traffic into the tunnel. Depending on the router products used this may be done by creating routes to a tunnel by name, by address, or by interface.

If multiple tunnels are defined or IPv6 interfaces, you must be selective with static routes, policy based routing, or even let the interior gateway protocol (IGP) make the decision since a ipv4 or ipv6 address has been configured on the tunnel. The key is the administrator should carefully plan and configure or let the IGP determine what goes into each tunnel.

NOTE: Nessus did not perform this check as it requires manual verification to identify the tunnel endpoints, then review all routing devices to ensure the tunnel entry point is not used as a default route.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

The SA must carefully plan and configure or let IGP determine what goes into each tunnel.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CAT|II, Rule-ID|SV-20504r2_rule, STIG-ID|NET-TUNL-012, Vuln-ID|V-18790

Plugin: Juniper

Control ID: 43fa1ca47222fda49aca14c1fb4dc42ad34a17db0d3bbd36435071a22bd8051b