STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must enable Unidirectional Link Detection (UDLD) to protect against one-way connections.

DISA Rule

SV-273687r1110990_rule

Vulnerability Number

V-273687

Group Title

SRG-NET-000512-L2S-000004

Rule Version

RCKS-L2S-000190

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to enable UDLD to protect against one-way connections.

1. On a port for untagged control packets:
Router(config)# link-keepalive ethernet 1/1/1

2. Optional trunk group:
Router(config)# link-keepalive ethernet 1/1/1 ethernet 1/1/2

Note: To receive and send UDLD control packets tagged with a specific VLAN ID:

Router(config)# link-keepalive ethernet 1/1/18 vlan 22

Check Contents

Review configuration for UDLD configuration ("link keep-alive").

Router# show link-keepalive
Total link-keepalive enabled ports: 4
Keepalive Retries: 3 Keepalive Interval: 1 Sec.
Port Physical Link Logical Link State Link-vlan
1/1/1 up up FORWARDING 3
1/1/2 up up FORWARDING
1/1/3 down down DISABLED
1/1/4 up down DISABLED

If UDLD is not configured to protect against one-way connections, this is a finding.

Vulnerability Number

V-273687

Documentable

False

Rule Version

RCKS-L2S-000190

Severity Override Guidance

Review configuration for UDLD configuration ("link keep-alive").

Router# show link-keepalive
Total link-keepalive enabled ports: 4
Keepalive Retries: 3 Keepalive Interval: 1 Sec.
Port Physical Link Logical Link State Link-vlan
1/1/1 up up FORWARDING 3
1/1/2 up up FORWARDING
1/1/3 down down DISABLED
1/1/4 up down DISABLED

If UDLD is not configured to protect against one-way connections, this is a finding.

Check Content Reference

M

Target Key

5697