STIGQter STIGQter: STIG Summary: RUCKUS ICX Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

The RUCKUS ICX switch must have all user-facing or untrusted ports configured as access switch ports.

DISA Rule

SV-273692r1110995_rule

Vulnerability Number

V-273692

Group Title

SRG-NET-000512-L2S-000011

Rule Version

RCKS-L2S-000250

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable trunking on all user-facing or untrusted switch ports.

1. Access Ports:
device(config)# vlan 222 name access
device(config-vlan-222)# untagged ethernet 1/1/2 to 1/1/48

2. Trunk Port:
device(config-vlan-222)# tagged ethernet 1/2/1

Check Contents

Review the switch configurations and examine all user-facing or untrusted switch ports.

device#show vlans
Total PORT-VLAN entries: 2
Maximum PORT-VLAN entries: 1024

Legend: [Stk=Stack-Id, S=Slot]

PORT-VLAN 222, Name Access, Priority level0, On
Untagged Ports: (U1/M1) 1 2 3 4 5 6 7 8 9 10 11 12
Untagged Ports: (U1/M1) 13 14 15 17 18 19 20 21 22 23 24 25
Untagged Ports: (U1/M1) 26 27 28 29 30 31 32 33 34 35 36 37
Untagged Ports: (U1/M1) 38 39 40 41 43 44 45 46 47 48
Untagged Ports: (U1/M2) 1 2 3 4 5 6 7 8
Tagged Ports: (U1/M2) 1
Mac-Vlan Ports: None
Monitoring: Disabled

PORT-VLAN 333, Name trunk, Priority level0, Off
Untagged Ports: None
Tagged Ports: (U1/M2) 1
Mac-Vlan Ports: None
Monitoring: Disabled
device#

If all user-facing or untrusted ports are not configured as access (i.e., untagged) ports, this is a finding.

Vulnerability Number

V-273692

Documentable

False

Rule Version

RCKS-L2S-000250

Severity Override Guidance

Review the switch configurations and examine all user-facing or untrusted switch ports.

device#show vlans
Total PORT-VLAN entries: 2
Maximum PORT-VLAN entries: 1024

Legend: [Stk=Stack-Id, S=Slot]

PORT-VLAN 222, Name Access, Priority level0, On
Untagged Ports: (U1/M1) 1 2 3 4 5 6 7 8 9 10 11 12
Untagged Ports: (U1/M1) 13 14 15 17 18 19 20 21 22 23 24 25
Untagged Ports: (U1/M1) 26 27 28 29 30 31 32 33 34 35 36 37
Untagged Ports: (U1/M1) 38 39 40 41 43 44 45 46 47 48
Untagged Ports: (U1/M2) 1 2 3 4 5 6 7 8
Tagged Ports: (U1/M2) 1
Mac-Vlan Ports: None
Monitoring: Disabled

PORT-VLAN 333, Name trunk, Priority level0, Off
Untagged Ports: None
Tagged Ports: (U1/M2) 1
Mac-Vlan Ports: None
Monitoring: Disabled
device#

If all user-facing or untrusted ports are not configured as access (i.e., untagged) ports, this is a finding.

Check Content Reference

M

Target Key

5697