STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.

DISA Rule

SV-273683r1110986_rule

Vulnerability Number

V-273683

Group Title

SRG-NET-000362-L2S-000027

Rule Version

RCKS-L2S-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.

1. Enter global configuration mode:
device# configure terminal
device(config)# ip arp inspection vlan 2

Optional Step 2: Apply to multiple VLANs:
device# configure terminal
device(config)# ip arp inspection vlan 100 to 150 160 170 to 200

Check Contents

Review list of VLANs with ARP inspection configured.

ICX#show ip arp inspection
IP ARP inspection enabled on 1 VLAN(s):
VLAN(s): 16

If ARP Inspection is not enabled on all user VLANs, this is a finding.

Vulnerability Number

V-273683

Documentable

False

Rule Version

RCKS-L2S-000150

Severity Override Guidance

Review list of VLANs with ARP inspection configured.

ICX#show ip arp inspection
IP ARP inspection enabled on 1 VLAN(s):
VLAN(s): 16

If ARP Inspection is not enabled on all user VLANs, this is a finding.

Check Content Reference

M

Target Key

5697