STIGQter STIGQter: STIG Summary: Dell OS10 Switch Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.

DISA Rule

SV-269961r1052492_rule

Vulnerability Number

V-269961

Group Title

SRG-NET-000362-L2S-000027

Rule Version

OS10-L2S-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have DAI enabled on all user VLANs as shown in the example below:

OS10(config)# interface range vlan 200-201
OS10(conf-range-vl-200-201)# arp inspection

Check Contents

Review the switch configuration to verify that DAI feature is enabled on all user VLANs.

Verify that each user VLAN has arp inspection enabled.

!
interface vlan200
no shutdown
arp inspection
!
interface vlan201
no shutdown
arp inspection

If ARP inspection is not enabled on all user VLANs, this is a finding.

Vulnerability Number

V-269961

Documentable

False

Rule Version

OS10-L2S-000150

Severity Override Guidance

Review the switch configuration to verify that DAI feature is enabled on all user VLANs.

Verify that each user VLAN has arp inspection enabled.

!
interface vlan200
no shutdown
arp inspection
!
interface vlan201
no shutdown
arp inspection

If ARP inspection is not enabled on all user VLANs, this is a finding.

Check Content Reference

M

Target Key

5667