Check: JUEX-RT-000900
Juniper EX Series Switches Router STIG:
JUEX-RT-000900
(in versions v1 r3 through v1 r1)
Title
The Juniper MPLS router must be configured to synchronize IGP and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange. (Cat III impact)
Discussion
Packet loss can occur when an IGP adjacency is established and the router begins forwarding packets using the new adjacency before the LDP label exchange completes between the peers on that link. Packet loss can also occur if an LDP session closes and the router continues to forward traffic using the link associated with the LDP peer rather than an alternate pathway with a fully synchronized LDP session. The MPLS LDP-IGP Synchronization feature provides a means to synchronize LDP with OSPF or IS-IS to minimize MPLS packet loss. When an IGP adjacency is established on a link but LDP-IGP synchronization is not yet achieved or is lost, the IGP will advertise the max-metric on that link.
Check Content
Review the router OSPF or IS-IS configuration. Verify that LDP will synchronize with the link-state routing protocol. [edit protocols] ospf { area <number> { interface <name>.<logical unit> { authentication { md5 <key number> key "$8$aes256-gcm$hmac-sha2-256$100$LfJ7NdAYx/0$+4wGg1QJKLzkaAmVCGxBUQ$n0XxNofUtXE8aoJBhFNDDQ$uIDW/H+VY6U"; ## SECRET-DATA } ldp-synchronization { hold-time 10; } } interface <name>.<logical unit> { ipsec-sa <name>; ldp-synchronization { hold-time 10; } } } } ldp { interface <name>.<logical unit>; } -OR- isis { interface <name>.<logical unit> { ldp-synchronization { hold-time 10; } } level 1 authentication-key-chain <name>; level 2 authentication-key-chain <name>; } mpls { interface <name>.<logical unit>; } If the router is not configured to synchronize IGP and LDP, this is a finding.
Fix Text
Configure the MPLS router to synchronize IGP and LDP, minimizing packet loss when an IGP adjacency is established prior to LDP peers completing label exchange. set protocols ospf area <number> interface <name>.<logical unit> authentication md5 <key number> <PSK> set protocols ospf area <number> interface <name>.<logical unit> ldp-synchronize hold-time 10 set protocols ldp interface <name>.<logical unit> -OR- set protocols isis level 1 authentication-key-chain <name> set protocols isis level 2 authentication-key-chain <name> set protocols isis interface <name>.<logical unit> ldp-synchronize hold-time 10 set protocols mpls interface <name>.<logical unit>
Additional Identifiers
Rule ID: SV-254062r844219_rule
Vulnerability ID: V-254062
Group Title: SRG-NET-000512-RTR-000003
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |