Check: JUEX-RT-000690
Juniper EX Series Switches Router STIG:
JUEX-RT-000690
(in versions v1 r3 through v1 r1)
Title
The Juniper multicast Rendezvous Point (RP) must be configured to rate limit the number of Protocol Independent Multicast (PIM) Register messages. (Cat II impact)
Discussion
When a new source starts transmitting in a PIM Sparse Mode network, the DR will encapsulate the multicast packets into register messages and forward them to the RP using unicast. This process can be taxing on the CPU for both the DR and the RP if the source is running at a high data rate and there are many new sources starting at the same time. This scenario can potentially occur immediately after a network failover. The rate limit for the number of register messages should be set to a relatively low value based on the known number of multicast sources within the multicast domain.
Check Content
Review the configuration of the RP to verify that it is rate limiting the number of multicast register messages. [edit protocols pim] rp { register-limit { maximum <1..65535>; } <additional configuration> } If the RP is not limiting multicast register messages, this is a finding.
Fix Text
Configure the RP to rate limit the number of multicast register messages. set protocols pim rp register-limit maximum <1..65535>
Additional Identifiers
Rule ID: SV-254041r844156_rule
Vulnerability ID: V-254041
Group Title: SRG-NET-000362-RTR-000121
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002355 |
The information system enforces access control decisions based on organization-defined security attributes that do not include the identity of the user or process acting on behalf of the user. |
CCI-002385 |
The information system protects against or limits the effects of organization-defined types of denial of service attacks by employing organization-defined security safeguards. |