Check: RCKS-RTR-000720
RUCKUS ICX Router STIG:
RCKS-RTR-000720
(in version v1 r1)
Title
The RUCKUS ICX Router must be configured to limit the number of mroute states resulting from Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Host Membership Reports. (Cat II impact)
Discussion
The current multicast paradigm can let any host join any multicast group at any time by sending an IGMP or MLD membership report to the DR. In a Protocol Independent Multicast (PIM) Sparse Mode network, the DR will send a PIM Join message for the group to the RP. Without any form of admission control, this can pose a security risk to the entire multicast domain - specifically the multicast routers along the shared tree from the DR to the RP that must maintain the mroute state information for each group join request. Hence, it is imperative that the DR is configured to limit the number of mroute state information that must be maintained to mitigate the risk of IGMP or MLD flooding.
Check Content
View the "show default value" output for the pim-hw-cache and pim6-hw-cache values. If either number is zero, this is a finding.
Fix Text
Configure the "system-max pim-hw-cache" and "system-max pim6-hw-cache" values to be above zero. (Reboot may be required to take effect.) ICX(config)#system-max pim-hw-cache 256 ICX(config)#system-max pim6-hw-cache 256
Additional Identifiers
Rule ID: SV-273639r1110942_rule
Vulnerability ID: V-273639
Group Title: SRG-NET-000362-RTR-000122
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002385 |
Protect against or limit the effects of organization-defined types of denial-of-service events. |
Controls
Number | Title |
---|---|
SC-5 |
Denial of Service Protection |