STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia layer 2 switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts.

DISA Rule

SV-283680r1204068_rule

Vulnerability Number

V-283680

Group Title

SRG-NET-000362-L2S-000021

Rule Version

NOKI-L2-000070

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the virtual private local area network service (VPLS) to have Root Guard enabled on all switch ports connecting to access layer switches and hosts.

Enable root guard for configured VPLS access ports where required using the command below:

- configure service vpls <vpls service id>
- sap <port id:vlan tag>
- stp root-guard

Check Contents

Review the switch topology and the configuration to verify Root Guard is enabled on all switch ports connecting to access layer switches and hosts.

Use the command below for each port connecting to access layer switches and verify "Root Guard" is enabled:

- show service id 10 sap 1/1/c3/10 stp | match "Root Guard"
Root Guard : Enabled Active Protocol : N/A

If the switch has not enabled Root Guard on all switch ports connecting to access layer switches and hosts, this is a finding.

Vulnerability Number

V-283680

Documentable

False

Rule Version

NOKI-L2-000070

Severity Override Guidance

Review the switch topology and the configuration to verify Root Guard is enabled on all switch ports connecting to access layer switches and hosts.

Use the command below for each port connecting to access layer switches and verify "Root Guard" is enabled:

- show service id 10 sap 1/1/c3/10 stp | match "Root Guard"
Root Guard : Enabled Active Protocol : N/A

If the switch has not enabled Root Guard on all switch ports connecting to access layer switches and hosts, this is a finding.

Check Content Reference

M

Target Key

5743