STIGQter STIGQter: STIG Summary: Layer 2 Switch Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 01 Apr 2026:

The layer 2 switch must be configured to protect against one-way connections.

DISA Rule

SV-206664r1188389_rule

Vulnerability Number

V-206664

Group Title

SRG-NET-000512

Rule Version

SRG-NET-000512-L2S-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch globally or per interface to protect against one-way connections.

Check Contents

If any of the switch ports have fiber optic interconnections with neighbors, review the switch configuration to verify that features such as Unidirectional Link Detection are enabled globally or on a per interface basis to protect against one-way connections. Doing so may also identify misconfigured copper cables.

If the switch has fiber optic interconnections with neighbors and is not configured to protect against one-way connections, this is a finding.

Vulnerability Number

V-206664

Documentable

False

Rule Version

SRG-NET-000512-L2S-000004

Severity Override Guidance

If any of the switch ports have fiber optic interconnections with neighbors, review the switch configuration to verify that features such as Unidirectional Link Detection are enabled globally or on a per interface basis to protect against one-way connections. Doing so may also identify misconfigured copper cables.

If the switch has fiber optic interconnections with neighbors and is not configured to protect against one-way connections, this is a finding.

Check Content Reference

M

Target Key

2913