DISA STIGS Viewer

The RUCKUS ICX multicast Rendezvous Pointerface (RP) Router must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of Protocol Independent Multicast (PIM) and Multicast Source Discovery Protocol (MSDP) source-active entries.

Overview

Finding ID Version Rule ID IA Controls Severity
V-273637 RCKS-RTR-000700 SV-273637r1110898_rule   Low
Description
MSDP peering between networks enables sharing of multicast source information. Enclaves with an existing multicast topology using PIM-SM can configure their RP routers to peer with MSDP routers. As a first step of defense against a denial-of-service (DoS) attack, all RP routers must limit the multicast forwarding cache to ensure that router resources are not saturated managing an overwhelming number of PIM and MSDP source-active entries.
STIG Date
RUCKUS ICX Router Security Technical Implementation Guide 2025-06-03

Details

Check Text (C-77728r1109931_chk)
View the "show default value" output for the msdp-sa-cache value. If that number is zero, this is a finding.
Fix Text (F-77633r1109932_fix)
Configure the "system-max msdp-sa-cache" value to be above zero. (Reboot may be required to take effect.)

ICX(config)#system-max msdp-sa-cache 1024