Free DISA STIG and SRG Library | Vaulted

V-3034

Network devices must authenticate all IGP peers.

Finding ID
NET0400
Rule ID
SV-3034r3_rule
Severity
Cat II
CCE
(None)
Group Title
Interior routing protocols are not authenticated.
CCI
(None)
Target Key
(None)
Documentable
No
Discussion

A rogue router could send a fictitious routing update to convince a site's premise router to send traffic to an incorrect or even a rogue destination. This diverted traffic could be analyzed to learn confidential information of the site's network, or merely used to disrupt the network's ability to effectively communicate with other networks.

Fix Text

Configure authentication for all IGP peers.

Check Content

Review the device configuration to determine if authentication is configured for all IGP peers. If authentication is not configured for all IGP peers, this is a finding.

Responsibility

Information Assurance Officer

IA Controls

ECSC-1