STIGQter STIGQter: STIG Summary: Cisco NX-OS Switch L2S Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 08 May 2020:

The Cisco switch must have Unknown Unicast Flood Blocking (UUFB) enabled.

DISA Rule

SV-110341r1_rule

Vulnerability Number

V-101237

Group Title

SRG-NET-000362-L2S-000024

Rule Version

CISC-L2-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have Unknown Unicast Flood Blocking (UUFB) enabled as shown in the configuration example below:

SW1(config)# int e1/1-32
SW1(config-if-range)# switchport block unicast
SW1(config-if-range)# end

Check Contents

Review the switch configuration to verify that UUFB is enabled on all access switch ports as shown in the configuration example below:

interface Ethernet1/1
switchport block unicast

interface Ethernet1/2
switchport block unicast



interface Ethernet1/32
switchport block unicast

If any access switch ports do not have UUFB enabled, this is a finding.

Vulnerability Number

V-101237

Documentable

False

Rule Version

CISC-L2-000120

Severity Override Guidance

Review the switch configuration to verify that UUFB is enabled on all access switch ports as shown in the configuration example below:

interface Ethernet1/1
switchport block unicast

interface Ethernet1/2
switchport block unicast



interface Ethernet1/32
switchport block unicast

If any access switch ports do not have UUFB enabled, this is a finding.

Check Content Reference

M

Target Key

3551

Comments