STIGQter STIGQter: STIG Summary: Cisco NX OS Switch L2S Security Technical Implementation Guide Version: 3 Release: 4 Benchmark Date: 01 Jul 2026:

The Cisco switch must not have any switchports assigned to the native VLAN.

DISA Rule

SV-220696r991953_rule

Vulnerability Number

V-220696

Group Title

SRG-NET-000512-L2S-000013

Rule Version

CISC-L2-000270

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure all access switch ports to a VLAN other than the native VLAN.

Check Contents

Review the switch configurations and examine all access switch ports. Verify that they do not belong to the native VLAN as shown in the example below:

interface Ethernet0/1
switchport
switchport mode trunk
switchport trunk native vlan 44

interface Ethernet0/2
switchport
switchport access vlan 11

interface Ethernet0/3
switchport
switchport access vlan 12

If any access switch ports have been assigned to the same VLAN ID as the native VLAN, this is a finding.

Vulnerability Number

V-220696

Documentable

False

Rule Version

CISC-L2-000270

Severity Override Guidance

Review the switch configurations and examine all access switch ports. Verify that they do not belong to the native VLAN as shown in the example below:

interface Ethernet0/1
switchport
switchport mode trunk
switchport trunk native vlan 44

interface Ethernet0/2
switchport
switchport access vlan 11

interface Ethernet0/3
switchport
switchport access vlan 12

If any access switch ports have been assigned to the same VLAN ID as the native VLAN, this is a finding.

Check Content Reference

M

Target Key

4073