STIGQter STIGQter: STIG Summary: Arista MLS EOS 4.X L2S Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Arista MLS switch must have STP Loop Guard enabled on all nondesignated STP switch ports.

DISA Rule

SV-255972r1107168_rule

Vulnerability Number

V-255972

Group Title

SRG-NET-000362-L2S-000023

Rule Version

ARST-L2-000070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Arista MLS switch for STP Loop Guard globally with the following command:

switch(config)#spanning-tree guard loop default
switch(config)#

Alternatively, configure Loop Guard on each interface:

switch(config-if-Eth6)# spanning-tree guard loop

Check Contents

Review the Arista MLS switch configuration to verify that STP Loop Guard is enabled. It can be enabled globally or applied to an interface.

Note: Arista uses STP Loop guard to protect against one-way connections.

switch# sh run | sec spanning-tree
spanning-tree guard loop default

Or,

interface Ethernet6
spanning-tree guard loop

If STP Loop Guard is not configured globally or on nondesignated STP ports, this is a finding.

Vulnerability Number

V-255972

Documentable

False

Rule Version

ARST-L2-000070

Severity Override Guidance

Review the Arista MLS switch configuration to verify that STP Loop Guard is enabled. It can be enabled globally or applied to an interface.

Note: Arista uses STP Loop guard to protect against one-way connections.

switch# sh run | sec spanning-tree
spanning-tree guard loop default

Or,

interface Ethernet6
spanning-tree guard loop

If STP Loop Guard is not configured globally or on nondesignated STP ports, this is a finding.

Check Content Reference

M

Target Key

5512