STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must have Bridge Protocol Data Unit (BPDU) Guard enabled on all user-facing or untrusted access switch ports.

DISA Rule

SV-273678r1110981_rule

Vulnerability Number

V-273678

Group Title

SRG-NET-000362-L2S-000022

Rule Version

RCKS-L2S-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure switch BPDU Guard enabled:

1. Global Config mode:
Router# configure terminal

2. Interface level mode:
Router(config)# interface ethernet 1/1/1

3. Implement stp-bpdu-guard:
Router(config-if-e1000-1/1/1)# stp-bpdu-guard

4. Save:
Router#write memory

Check Contents

Review switch port configuration on all untrusted access ports.

!
interface ethernet x/x/x
spanning-tree root-protect
stp-bpdu-guard
!

If untrusted access switch ports are not configured for BPDU Guard, this is a finding.

Vulnerability Number

V-273678

Documentable

False

Rule Version

RCKS-L2S-000100

Severity Override Guidance

Review switch port configuration on all untrusted access ports.

!
interface ethernet x/x/x
spanning-tree root-protect
stp-bpdu-guard
!

If untrusted access switch ports are not configured for BPDU Guard, this is a finding.

Check Content Reference

M

Target Key

5697