STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia layer 2 switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user virtual local area networks (VLANs).

DISA Rule

SV-283685r1204130_rule

Vulnerability Number

V-283685

Group Title

SRG-NET-000362-L2S-000027

Rule Version

NOKI-L2-000130

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The system evaluates ARP replies and requests received on a SAP with arp-reply-agent enabled against the anti-spoof filter entries associated with the ingress SAP. ARPs from unknown hosts on the SAP are discarded when anti-spoof filtering is enabled.

Configure the Nokia router VPLS service to enable DHCP snooping at all points where DHCP messages requiring snooping enter the VPLS service:

- configure service vpls <service id> sap <sap id> dhcp snoop

Populate the DHCP lease state information extracted from snooped DHCP ACK messages. If the optional number "lease state table entries allowed" is omitted, only a single entry is allowed. Once the maximum number of entries has been reached, subsequent lease state entries are not allowed, and DHCP ACK messages are discarded.

- configure service vpls <service id> sap <sap id> dhcp lease-populate <number of DHCP leases allowed>

Enable anti-spoof filtering for untrusted VPLS service access points. Anti-spoof type can be ip, ip-mac, or mac.

When type "ip" is used, only the source IP address is used in its lookup. The "ip-mac" type uses both IP address and the source MAC address in its lookup, while the "mac" type uses only the source MAC address in its lookup.

If an entry does not match the ingress packet, the packet is silently discarded while incrementing the SAP discard counter.

- configure service vpls <service id> sap <sap id> anti-spoof <anti-spoof type>

Enable arp-reply-agent:

- configure service vpls sap <sap id> arp-reply-agent

Check Contents

Review the virtual private local area network service (VPLS) configuration and verify an equivalent command for the DAI feature is enabled on all user VLANs.

Verify both "DHCP snooping" and "lease populate" options under DHCP result for each service access point (SAP) within a VPLS service:

-show service id 10 sap 1/1/c3/10 detail | match "Anti Spoofing"
Anti Spoofing : Ip-Mac Dynamic Hosts : Enabled

- show service id 10 sap 1/1/c3/10 detail | match "ARP Reply Agent"
ARP Reply Agent : Enabled Host Conn Verify : Disabled

Using the same command, verify "Anti Spoofing" is enabled with type IP-MAC, and "ARP Reply Agent" is also enabled.

If these are not enabled on all user VLANs, this is a finding.

Vulnerability Number

V-283685

Documentable

False

Rule Version

NOKI-L2-000130

Severity Override Guidance

Review the virtual private local area network service (VPLS) configuration and verify an equivalent command for the DAI feature is enabled on all user VLANs.

Verify both "DHCP snooping" and "lease populate" options under DHCP result for each service access point (SAP) within a VPLS service:

-show service id 10 sap 1/1/c3/10 detail | match "Anti Spoofing"
Anti Spoofing : Ip-Mac Dynamic Hosts : Enabled

- show service id 10 sap 1/1/c3/10 detail | match "ARP Reply Agent"
ARP Reply Agent : Enabled Host Conn Verify : Disabled

Using the same command, verify "Anti Spoofing" is enabled with type IP-MAC, and "ARP Reply Agent" is also enabled.

If these are not enabled on all user VLANs, this is a finding.

Check Content Reference

M

Target Key

5743