STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia layer 2 switch must have Dynamic Host Configuration Protocol (DHCP) snooping for all user virtual local area networks (VLANs) to validate DHCP messages from untrusted sources.

DISA Rule

SV-283683r1204077_rule

Vulnerability Number

V-283683

Group Title

SRG-NET-000362-L2S-000025

Rule Version

NOKI-L2-000110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

Configure DHCP snooping for all user service access points:

- configure service vpls <vpls service id> sap <sap id> dhcp
- snoop
- no shutdown

Check Contents

Use the command below for each virtual private local area network service (VPLS) and verify the status of DHCP for all user VLANs:

- show service id 10 dhcp summary

DHCP Summary, service 10

Sap/Sdp Snoop Used/ Arp Reply Info Admin
Provided Agent Option State

sap:1/1/c3/10 Yes 0/1 Yes Keep Up

Number of Entries : 1

If the switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Vulnerability Number

V-283683

Documentable

False

Rule Version

NOKI-L2-000110

Severity Override Guidance

Use the command below for each virtual private local area network service (VPLS) and verify the status of DHCP for all user VLANs:

- show service id 10 dhcp summary

DHCP Summary, service 10

Sap/Sdp Snoop Used/ Arp Reply Info Admin
Provided Agent Option State

sap:1/1/c3/10 Yes 0/1 Yes Keep Up

Number of Entries : 1

If the switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Check Content Reference

M

Target Key

5743