STIGQter STIGQter: STIG Summary: Dell OS10 Switch Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must have BPDU Guard enabled on all user-facing or untrusted access switch ports.

DISA Rule

SV-269956r1052254_rule

Vulnerability Number

V-269956

Group Title

SRG-NET-000362-L2S-000022

Rule Version

OS10-L2S-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Dell OS10 Switch to enable BPDU Guard on all user-facing or untrusted access switch ports, as shown in the example below:

OS10(config)# interface ethernet 1/1/1
OS10(conf-if-eth1/1/1)# spanning-tree bpduguard enable

Check Contents

Review the Dell OS10 Switch topology as well as the switch configuration to verify that BPDU Guard is enabled on all user-facing or untrusted access switch ports.

For each user-facing or untrusted access switch port, execute the following:

OS10# show running-configuration interface ethernet <interface number>
Verify Root Guard is enabled: spanning-tree bpduguard enable

If the switch has not enabled BPDU Guard on all user-facing or untrusted access switch ports, this is a finding.

Vulnerability Number

V-269956

Documentable

False

Rule Version

OS10-L2S-000100

Severity Override Guidance

Review the Dell OS10 Switch topology as well as the switch configuration to verify that BPDU Guard is enabled on all user-facing or untrusted access switch ports.

For each user-facing or untrusted access switch port, execute the following:

OS10# show running-configuration interface ethernet <interface number>
Verify Root Guard is enabled: spanning-tree bpduguard enable

If the switch has not enabled BPDU Guard on all user-facing or untrusted access switch ports, this is a finding.

Check Content Reference

M

Target Key

5667