SV-283680r1204068_rule
V-283680
SRG-NET-000362-L2S-000021
NOKI-L2-000070
CAT III
10
Configure the virtual private local area network service (VPLS) to have Root Guard enabled on all switch ports connecting to access layer switches and hosts.
Enable root guard for configured VPLS access ports where required using the command below:
- configure service vpls <vpls service id>
- sap <port id:vlan tag>
- stp root-guard
Review the switch topology and the configuration to verify Root Guard is enabled on all switch ports connecting to access layer switches and hosts.
Use the command below for each port connecting to access layer switches and verify "Root Guard" is enabled:
- show service id 10 sap 1/1/c3/10 stp | match "Root Guard"
Root Guard : Enabled Active Protocol : N/A
If the switch has not enabled Root Guard on all switch ports connecting to access layer switches and hosts, this is a finding.
V-283680
False
NOKI-L2-000070
Review the switch topology and the configuration to verify Root Guard is enabled on all switch ports connecting to access layer switches and hosts.
Use the command below for each port connecting to access layer switches and verify "Root Guard" is enabled:
- show service id 10 sap 1/1/c3/10 stp | match "Root Guard"
Root Guard : Enabled Active Protocol : N/A
If the switch has not enabled Root Guard on all switch ports connecting to access layer switches and hosts, this is a finding.
M
5743