STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

DISA Rule

SV-273681r1111008_rule

Vulnerability Number

V-273681

Group Title

SRG-NET-000362-L2S-000025

Rule Version

RCKS-L2S-000130

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

1. Configure user VLANs for DHCP snooping.
ICX#configure terminal
ICX(config)#ip dhcp snooping vlan 100 to 101 150

2. Configure port(s) to be trusted.
ICX(config)# interface ethernet x/x/x
ICX(config-if-e1000-x/x/x) dhcp snooping trust

Check Contents

Review switch configuration for DHCP snooping on all user VLANs.

!
ip dhcp snooping vlan 100
!
interface ethernet x/x/x
port-name toward_dhcp_srvr
dhcp snooping trust

If DHCP Snooping is not configured on user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Vulnerability Number

V-273681

Documentable

False

Rule Version

RCKS-L2S-000130

Severity Override Guidance

Review switch configuration for DHCP snooping on all user VLANs.

!
ip dhcp snooping vlan 100
!
interface ethernet x/x/x
port-name toward_dhcp_srvr
dhcp snooping trust

If DHCP Snooping is not configured on user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Check Content Reference

M

Target Key

5697