The Cisco switch must manage excess bandwidth to limit the effects of packet-flooding types of denial-of-service (DoS) attacks.
DISA Rule
SV-220625r991847_rule
Vulnerability Number
V-220625
Group Title
SRG-NET-000193-L2S-000020
Rule Version
CISC-L2-000040
Severity
CAT II
CCI(s)
- CCI-001095 - Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.
- CCI-004866 - Employ organization-defined controls by type of denial-of-service to achieve the denial-of-service objective.
Weight
10
Fix Recommendation
Enable QoS on the switch:
SW1(config)#mls qos
Check Contents
Review the switch configuration to verify QoS has been enabled as shown below:
mls qos
If QoS has not been enabled, this is a finding.
Vulnerability Number
V-220625
Documentable
False
Rule Version
CISC-L2-000040
Severity Override Guidance
Review the switch configuration to verify QoS has been enabled as shown below:
mls qos
If QoS has not been enabled, this is a finding.
Check Content Reference
M
Target Key
4070