STIGQter STIGQter: STIG Summary: Dell OS10 Switch Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must have Source Address Validation (SAV) enabled on all user-facing or untrusted access switch ports.

DISA Rule

SV-269960r1052266_rule

Vulnerability Number

V-269960

Group Title

SRG-NET-000362-L2S-000026

Rule Version

OS10-L2S-000140

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Dell OS10 Switch to have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources, as shown in the example below:

Enable DHCP snooping globally in CONFIGURATION mode:

OS10(config)# ip dhcp snooping

Specify physical interfaces which are user facing or untrusted in INTERFACE mode:

OS10(config)# interface ethernet 1/1/24
OS10(conf-if-eth1/1/1)# ip dhcp snooping source-address-validation ipmac

Check Contents

Review the Dell OS10 Switch configuration and verify that SAV is enabled on all user-facing or untrusted access switch ports.

Verify that DHCP snooping is enabled globally:

ip dhcp snooping

Verify that interfaces attached to trusted DHCP servers are configured:

interface ethernet 1/1/4
ip dhcp snooping trust

Enable source IP and MAC address validation in INTERFACE mode for each untrusted and user-facing port:

ip dhcp snooping source-address-validation ipmac

If the switch does not have DHCP snooping is enabled globally, a trusted DHCP server port specified, and Source Address Validation enabled for all user-facing or untrusted access switch ports, this is a finding.

Vulnerability Number

V-269960

Documentable

False

Rule Version

OS10-L2S-000140

Severity Override Guidance

Review the Dell OS10 Switch configuration and verify that SAV is enabled on all user-facing or untrusted access switch ports.

Verify that DHCP snooping is enabled globally:

ip dhcp snooping

Verify that interfaces attached to trusted DHCP servers are configured:

interface ethernet 1/1/4
ip dhcp snooping trust

Enable source IP and MAC address validation in INTERFACE mode for each untrusted and user-facing port:

ip dhcp snooping source-address-validation ipmac

If the switch does not have DHCP snooping is enabled globally, a trusted DHCP server port specified, and Source Address Validation enabled for all user-facing or untrusted access switch ports, this is a finding.

Check Content Reference

M

Target Key

5667