STIGQter STIGQter: STIG Summary: Juniper EX Series Switches Layer 2 Switch Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Juniper EX switch must be configured to enable Root Protection on STP switch ports connecting to access layer switches.

DISA Rule

SV-253955r1082970_rule

Vulnerability Number

V-253955

Group Title

SRG-NET-000362-L2S-000021

Rule Version

JUEX-L2-000080

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have Root Protection enabled on all switch ports connecting to access layer switches and hosts using trunked interfaces.

set protocols mstp interface <interface name> no-root-port

Check Contents

Review the switch topology as well as the switch configuration to verify that Root Protection is enabled on all interfaces connecting to access layer switches.

[edit protocols]
mstp {
interface <interface name> {
no-root-port;
}
}

If Root Protection is not enabled on all interfaces connecting to access layer switches, this is a finding.

Vulnerability Number

V-253955

Documentable

False

Rule Version

JUEX-L2-000080

Severity Override Guidance

Review the switch topology as well as the switch configuration to verify that Root Protection is enabled on all interfaces connecting to access layer switches.

[edit protocols]
mstp {
interface <interface name> {
no-root-port;
}
}

If Root Protection is not enabled on all interfaces connecting to access layer switches, this is a finding.

Check Content Reference

M

Target Key

5478