STIGQter STIGQter: STIG Summary: Juniper EX Series Switches Layer 2 Switch Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Juniper layer 2 switch must be configured to disable all dynamic VLAN registration protocols.

DISA Rule

SV-253950r1188386_rule

Vulnerability Number

V-253950

Group Title

SRG-NET-000168-L2S-000019

Rule Version

JUEX-L2-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to disable all dynamic VLAN registration protocols.

delete protocols mvrp

Check Contents

Review the switch configuration to verify if dynamic VLAN registration protocols are enabled. If dynamic VLAN registration protocols are enabled, verify that authentication has been configured.

Juniper switches do not support VTP. Although Juniper switches support MVRP, it is disabled by default (there is no [edit protocols mvrp] stanza). Verify MVRP is not enabled as shown below.

[edit protocols]
mvrp {
interface <name>;
}

If dynamic VLAN registration protocols have been configured on the switch and are not authenticating messages with a hash function using the most secured cryptographic algorithm available, this is a finding.

Vulnerability Number

V-253950

Documentable

False

Rule Version

JUEX-L2-000030

Severity Override Guidance

Review the switch configuration to verify if dynamic VLAN registration protocols are enabled. If dynamic VLAN registration protocols are enabled, verify that authentication has been configured.

Juniper switches do not support VTP. Although Juniper switches support MVRP, it is disabled by default (there is no [edit protocols mvrp] stanza). Verify MVRP is not enabled as shown below.

[edit protocols]
mvrp {
interface <name>;
}

If dynamic VLAN registration protocols have been configured on the switch and are not authenticating messages with a hash function using the most secured cryptographic algorithm available, this is a finding.

Check Content Reference

M

Target Key

5478