NET0166 - The AG network service provider IP addresses are not redistributed into or advertised to the NIPRNet - EIGRP

Information

Unsolicited traffic that may inadvertently attempt to enter the NIPRNet by traversing the enclave's premise router can be avoided by not redistributing NIPRNet routes into the AG.

Solution

Use distribute lists prefix lists to insure AG routes are not redistributed into the NIPRNet BGP or sites IGP (OSPF, EIGRP, RIP, etc).

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(20), CAT|III, Rule-ID|SV-4624r2_rule, STIG-ID|NET0166, Vuln-ID|V-4624

Plugin: Juniper

Control ID: c45b01d94dfd58589982f8075bc65958e8380e30e7ea2583b4013c41cba75d62