STIGQter STIGQter: STIG Summary:

Dell OS10 Switch Layer 2 Switch Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 10 Dec 2024

CheckedNameTitle
SV-269953r1052245_ruleThe Dell OS10 Switch must uniquely identify all network-connected endpoint devices before establishing any connection.
SV-269954r1052477_ruleThe Dell OS10 Switch must manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks.
SV-269955r1052251_ruleThe Dell OS10 Switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts.
SV-269956r1052254_ruleThe Dell OS10 Switch must have BPDU Guard enabled on all user-facing or untrusted access switch ports.
SV-269957r1052257_ruleThe Dell OS10 Switch must have STP Loop Guard enabled on all nondesignated STP switch ports.
SV-269958r1052260_ruleThe Dell OS10 Switch must have Unknown Unicast Flood Blocking (UUFB) enabled.
SV-269959r1052263_ruleThe Dell OS10 Switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.
SV-269960r1052266_ruleThe Dell OS10 Switch must have Source Address Validation (SAV) enabled on all user-facing or untrusted access switch ports.
SV-269961r1052492_ruleThe Dell OS10 Switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.
SV-269962r1052327_ruleThe Dell OS10 Switch must have Storm Control configured on all host-facing switch ports.
SV-269963r1052275_ruleThe Dell OS10 Switch must have IGMP or MLD Snooping configured on all VLANs
SV-269964r1052278_ruleThe Dell OS10 Switch must implement Rapid Spanning Tree Protocol (STP) where VLANs span multiple switches with redundant links.
SV-269965r1052281_ruleThe Dell OS10 Switch must enable Far-End Failure Detection (FEFD) to protect against one-way connections.
SV-269966r1052284_ruleThe Dell OS10 Switch must have all disabled switch ports assigned to an unused VLAN.
SV-269967r1052287_ruleThe Dell OS10 Switch must not have the default VLAN assigned to any host-facing switch ports.
SV-269968r1052290_ruleThe Dell OS10 Switch must have the default VLAN pruned from all trunk ports that do not require it.
SV-269969r1052293_ruleThe Dell OS10 Switch must not use the default VLAN for management traffic.
SV-269970r1052296_ruleThe Dell OS10 Switch must have all user-facing or untrusted ports configured as access switch ports.
SV-269971r1052299_ruleThe Dell OS10 Switch must not have any switch ports assigned to the native VLAN.
SV-269972r1052302_ruleThe Dell OS10 Switch must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.