STIGQter STIGQter: STIG Summary: Arista MLS EOS 4.X L2S Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Arista MLS switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts.

DISA Rule

SV-255970r882252_rule

Vulnerability Number

V-255970

Group Title

SRG-NET-000362-L2S-000021

Rule Version

ARST-L2-000050

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

The Arista MLS switch must be configured for spanning-tree guard root mode on all ports connecting to the access layer interface.

Configure Arista MLS switch Ethernet interface with the following commands:

switch#config 
switch(config)interface Ethernet[X] 
switch(config-if-Et[X])#spanning-tree guard root
switch(config-if-Et[X])#exit
!

Check Contents

Review the Arista MLS switch topology as well as the configuration to verify that root guard is enabled on switch ports facing switches that are downstream from the root bridge.

Example:
switch#sh run | sec guard root
interface Ethernet37
spanning-tree guard root

If the Arista MLS switch has not enabled guard root on all ports connecting to the access layer where the root bridge must not appear, this is a finding.

Vulnerability Number

V-255970

Documentable

False

Rule Version

ARST-L2-000050

Severity Override Guidance

Review the Arista MLS switch topology as well as the configuration to verify that root guard is enabled on switch ports facing switches that are downstream from the root bridge.

Example:
switch#sh run | sec guard root
interface Ethernet37
spanning-tree guard root

If the Arista MLS switch has not enabled guard root on all ports connecting to the access layer where the root bridge must not appear, this is a finding.

Check Content Reference

M

Target Key

5512