Check: SRG-NET-000230-RTR-000002
Router SRG:
SRG-NET-000230-RTR-000002
(in versions v4 r3 through v4 r1)
Title
The BGP router must be configured to use a unique key for each autonomous system (AS) that it peers with. (Cat II impact)
Discussion
If the same keys are used between eBGP neighbors, the chance of a hacker compromising any of the BGP sessions increases. It is possible that a malicious user exists in one autonomous system who would know the key used for the eBGP session. This user would then be able to hijack BGP sessions with other trusted neighbors.
Check Content
Interview the ISSM and router administrator to determine if unique keys are being used. If unique keys are not being used, this is a finding.
Fix Text
Configure all eBGP routers with unique keys for each eBGP neighbor that it peers with.
Additional Identifiers
Rule ID: SV-216983r945862_rule
Vulnerability ID: V-216983
Group Title: SRG-NET-000230
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
CCI-001184 |
The information system protects the authenticity of communications sessions. |
CCI-002205 |
The information system uniquely identifies and authenticates source by organization, system, application, and/or individual for information transfer. |