STIGQter STIGQter: STIG Summary:

Juniper EX Series Switches Layer 2 Switch Security Technical Implementation Guide

Version: 2

Release: 5 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-253948r843877_ruleThe Juniper EX switch must be configured to disable non-essential capabilities.
SV-253949r843880_ruleThe Juniper EX switch must be configured to uniquely identify all network-connected endpoint devices before establishing any connection.
SV-253950r1188386_ruleThe Juniper layer 2 switch must be configured to disable all dynamic VLAN registration protocols.
SV-253951r1082966_ruleThe Juniper EX switch must be configured to manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks.
SV-253952r1082341_ruleThe Juniper EX switch must be configured to permit authorized users to select a user session to capture.
SV-253953r1082342_ruleThe Juniper EX switch must be configured to permit authorized users to remotely view, in real time, all content related to an established user session from a component separate from the layer 2 switch.
SV-253954r1082969_ruleThe Juniper EX switch must be configured to authenticate all network-connected endpoint devices before establishing any connection.
SV-253955r1082970_ruleThe Juniper EX switch must be configured to enable Root Protection on STP switch ports connecting to access layer switches.
SV-253956r843901_ruleThe Juniper EX switch must be configured to enable BPDU Protection on all user-facing or untrusted access switch ports.
SV-253957r843904_ruleThe Juniper EX switch must be configured to enable STP Loop Protection on all non-designated STP switch ports.
SV-253959r1212011_ruleThe Juniper EX switch must be configured to enable DHCP snooping for all user VLANs with active access interfaces to validate DHCP messages from untrusted sources.
SV-253960r1212014_ruleThe Juniper EX switch must be configured to enable IP Source Guard on all user-facing or untrusted access VLANs with active access interfaces.
SV-253961r1212017_ruleThe Juniper EX switch must be configured to enable Dynamic Address Resolution Protocol (ARP) Inspection (DAI) on all user VLANs with active access interfaces.
SV-253962r843919_ruleThe Juniper EX switch must be configured to enable Storm Control on all host-facing access interfaces.
SV-253963r843922_ruleThe Juniper EX switch must be configured to enable IGMP or MLD Snooping on all VLANs.
SV-253964r843925_ruleIf STP is used, the Juniper EX switch must be configured to implement Rapid STP, or Multiple STP, where VLANs span multiple switches with redundant links.
SV-253965r1188389_ruleThe Juniper EX switch must be configured to verify two-way connectivity on all interswitch trunked interfaces.
SV-253966r1082973_ruleThe Juniper EX switch must be configured to assign all explicitly disabled access interfaces to an unused VLAN.
SV-253967r997518_ruleThe Juniper EX switch must not be configured with VLANs used for L2 control traffic assigned to any host-facing access interface.
SV-253968r843937_ruleThe Juniper EX switch must be configured to prune the default VLAN from all trunked interfaces that do not require it.
SV-253969r997519_ruleThe Juniper EX switch must not use the default VLAN for management traffic.
SV-253970r1082976_ruleThe Juniper EX switch must be configured to set all enabled user-facing or untrusted ports as access interfaces.
SV-253971r843946_ruleThe Juniper EX switch must not have a native VLAN ID assigned, or have a unique native VLAN ID, for all 802.1q trunk links.
SV-253972r843949_ruleThe Juniper EX switch must not have any access interfaces assigned to a VLAN configured as native for any trunked interface.