STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must have IGMP or MLD Snooping configured on all VLANs.

DISA Rule

SV-273685r1110988_rule

Vulnerability Number

V-273685

Group Title

SRG-NET-000512-L2S-000002

Rule Version

RCKS-L2S-000170

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure IGMP or MLD snooping for IPv4 and IPv6 multicast traffic respectively for each VLAN.

Enable IGMP Globally:
ICX# configure terminal
ICX(config)# ip multicast active
Note: If the active keyword is not specified, the default mode is passive.
Optional: IGMP Version
ICX(config)# ip multicast version 3

Other options:

Configure by vlan:
ICX(config)# vlan 20
ICX(config-vlan-20)# multicast active
ICX(config-vlan-20)# multicast version 3
ICX(config-vlan-20)# multicast port-version 3 ethernet 1/2/4 to 1/2/6

Static group assignment:
ICX(config-vlan-20)# multicast static-group 224.1.1.1 count 2 ethernet 1/1/3 ethernet 1/1/5 to 1/1/7

Check Contents

Review the switch configuration for IGMP and MLD snooping.

!
ip multicast
ipv6 multicast
!

If IGMP or MLD snooping are not configured for all VLANs, this is a finding.

Vulnerability Number

V-273685

Documentable

False

Rule Version

RCKS-L2S-000170

Severity Override Guidance

Review the switch configuration for IGMP and MLD snooping.

!
ip multicast
ipv6 multicast
!

If IGMP or MLD snooping are not configured for all VLANs, this is a finding.

Check Content Reference

M

Target Key

5697