STIGQter STIGQter: STIG Summary: Layer 2 Switch Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 01 Apr 2026:

When using VLAN Trunk Protocol (VTP) or similar features, the layer 2 switch must authenticate all VTP messages with a hash function using the most secured cryptographic algorithm available.

DISA Rule

SV-206648r1188386_rule

Vulnerability Number

V-206648

Group Title

SRG-NET-000168

Rule Version

SRG-NET-000168-L2S-000019

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to authenticate all VTP (or similarly named vendor feature) messages with a hash function using the most secured cryptographic algorithm available.

Check Contents

Review the switch configuration to verify if VTP or (similarly named vendor features) is enabled. If VTP is enabled, verify that authentication has been configured.

If VTP has been configured on the switch and is not authenticating VTP messages with a hash function using the most secured cryptographic algorithm available, this is a finding.

Vulnerability Number

V-206648

Documentable

False

Rule Version

SRG-NET-000168-L2S-000019

Severity Override Guidance

Review the switch configuration to verify if VTP or (similarly named vendor features) is enabled. If VTP is enabled, verify that authentication has been configured.

If VTP has been configured on the switch and is not authenticating VTP messages with a hash function using the most secured cryptographic algorithm available, this is a finding.

Check Content Reference

M

Target Key

2913