CCI|CCI-001097

Title

Monitor and control communications at the external managed interfaces to the system and at key managed interfaces within the system.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AMLS-L3-000290 - Arista MLS must configure the maximum hop limit value to at least 32.AristaDISA STIG Arista MLS DCS-7000 Series RTR V1R2
AMLS-L3-000290 - The Arista Multilayer Switch must configure the maximum hop limit value to at least 32.AristaDISA STIG Arista MLS DCS-7000 Series RTR v1r4
AMLS-L3-000290 - The Arista Multilayer Switch must configure the maximum hop limit value to at least 32.AristaDISA STIG Arista MLS DCS-7000 Series RTR v1r3
ARST-RT-000340 - The Arista router must be configured to restrict traffic destined to itself.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000340 - The Arista router must be configured to restrict traffic destined to itself.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000350 - The Arista router must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000350 - The Arista router must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000370 - The Arista perimeter router must be configured to filter ingress traffic at the external interface on an inbound direction.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000370 - The Arista perimeter router must be configured to filter ingress traffic at the external interface on an inbound direction.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000380 - The Arista perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000380 - The Arista perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000390 - The Arista BGP router must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000390 - The Arista BGP router must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000400 - The Arista router must be configured to block any traffic that is destined to IP core infrastructure.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000400 - The Arista router must be configured to block any traffic that is destined to IP core infrastructure.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000410 - The Arista router must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000410 - The Arista router must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000420 - The out-of-band management (OOBM) Arista gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000420 - The out-of-band management (OOBM) Arista gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000430 - The out-of-band management (OOBM) Arista gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000430 - The out-of-band management (OOBM) Arista gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000440 - The Arista router must be configured to only permit management traffic that ingresses and egresses the OOBM interface.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
ARST-RT-000440 - The Arista router must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000650 - The Arista perimeter router must be configured to block all outbound management traffic.AristaDISA STIG Arista MLS EOS 4.2x Router v2r1
ARST-RT-000650 - The Arista perimeter router must be configured to block all outbound management traffic.AristaDISA STIG Arista MLS EOS 4.2x Router v1r1
CISC-RT-000120 - The Cisco router must be configured to protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS XE Router RTR v3r1
CISC-RT-000120 - The Cisco router must be configured to protect against or limit the effects of denial of service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS XE Router RTR v2r9
CISC-RT-000120 - The Cisco router must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS Router RTR v2r6
CISC-RT-000120 - The Cisco router must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS Router RTR v3r1
CISC-RT-000120 - The Cisco switch must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS XE Switch RTR v2r5
CISC-RT-000120 - The Cisco switch must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS Switch RTR v2r5
CISC-RT-000120 - The Cisco switch must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS Switch RTR v3r1
CISC-RT-000120 - The Cisco switch must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.CiscoDISA STIG Cisco IOS XE Switch RTR v3r1
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS Router RTR v2r1
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Router RTR v2r1
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Router RTR v2r2
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Router RTR v2r8
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Router RTR v2r6
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS Router RTR v2r4
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS-XR Router RTR v2r3
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Router RTR v2r3
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Router RTR v2r4
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS-XR Router RTR v3r1
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS-XR Router RTR v2r1
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS-XR Router RTR v2r2
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS Router RTR v1r4
CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS-XR Router RTR v2r4
CISC-RT-000130 - The Cisco switch must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS Switch RTR v2r1
CISC-RT-000130 - The Cisco switch must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco NX-OS Switch RTR v1r1
CISC-RT-000130 - The Cisco switch must be configured to restrict traffic destined to itself.CiscoDISA STIG Cisco IOS XE Switch RTR v1r1