STIGQter STIGQter: STIG Summary: Layer 2 Switch Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 01 Apr 2026:

The layer 2 switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

DISA Rule

SV-206658r856588_rule

Vulnerability Number

V-206658

Group Title

SRG-NET-000362

Rule Version

SRG-NET-000362-L2S-000025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

Check Contents

Review the switch configuration and verify that DHCP snooping is enabled on all user VLANs.

If the switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Vulnerability Number

V-206658

Documentable

False

Rule Version

SRG-NET-000362-L2S-000025

Severity Override Guidance

Review the switch configuration and verify that DHCP snooping is enabled on all user VLANs.

If the switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Check Content Reference

M

Target Key

2913