Check: RCKS-RTR-000460
RUCKUS ICX Router STIG:
RCKS-RTR-000460
(in version v1 r1)
Title
The RUCKUS ICX management network gateway must be configured to transport management traffic to the Network Operations Center (NOC) via dedicated circuit. (Cat II impact)
Discussion
When the production network is managed in-band or out-of-band (OOBM), the management network could be housed at a NOC that is located remotely at single or multiple interconnected sites. NOC interconnectivity, as well as connectivity between the NOC and the managed network, must be enabled using IPsec tunnels or dedicated circuits to provide the separation and integrity of the managed traffic.
Check Content
This requirement is not applicable for the DODIN Backbone. Review the network topology diagram to determine connectivity between the managed network and the NOC. Review the management network gateway router configuration to validate the path and interface that the management traffic traverses. If management traffic is not transported between the managed network and the NOC via dedicated circuit, this is a finding.
Fix Text
This requirement is not applicable for the DODIN Backbone. Deploy a dedicated circuit to transport management traffic between the managed network and the NOC.
Additional Identifiers
Rule ID: SV-273613r1110924_rule
Vulnerability ID: V-273613
Group Title: SRG-NET-000205-RTR-000009
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001097 |
Monitor and control communications at the external managed interfaces to the system and at key managed interfaces within the system. |
Controls
Number | Title |
---|---|
SC-7 |
Boundary Protection |