STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must not have the default VLAN assigned to any host-facing switch ports.

DISA Rule

SV-273689r1111059_rule

Vulnerability Number

V-273689

Group Title

SRG-NET-000512-L2S-000008

Rule Version

RCKS-L2S-000220

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove the assignment of the default VLAN from all access switch ports.

1. Remove the default VLAN.
Router(config-vlan-5)#tag ethernet 1/1/48
Added tagged port(s) ethernet 1/1/48 to port-vlan 5.
Router(config-vlan-5)#

2. Save the configuration.
Router(config-vlan-5)# write memory

Note: The Default VLAN ID can be configurable by the administrator.

Check Contents

Review the switch configurations and verify that no access switch ports have been assigned membership to the default VLAN.

Router#show vlans
PORT-VLAN 5, Name DEFAULT-VLAN], Priority level0, in single spanning tree domain
Untagged Ports: None
Tagged Ports: (U1/M1) 1 2 5 7 9 11
Mac-Vlan Ports: None
Monitoring: Disabled

If there are access switch ports assigned to the default VLAN, this is a finding.

Vulnerability Number

V-273689

Documentable

False

Rule Version

RCKS-L2S-000220

Severity Override Guidance

Review the switch configurations and verify that no access switch ports have been assigned membership to the default VLAN.

Router#show vlans
PORT-VLAN 5, Name DEFAULT-VLAN], Priority level0, in single spanning tree domain
Untagged Ports: None
Tagged Ports: (U1/M1) 1 2 5 7 9 11
Mac-Vlan Ports: None
Monitoring: Disabled

If there are access switch ports assigned to the default VLAN, this is a finding.

Check Content Reference

M

Target Key

5697