| Checked | Name | Title |
|---|
| ☐ | SV-283678r1204062_rule | The Nokia layer 2 switch must uniquely identify all network-connected endpoint devices before establishing any connection. |
| ☐ | SV-283679r1204137_rule | The Nokia layer 2 switch must manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks. |
| ☐ | SV-283680r1204068_rule | The Nokia layer 2 switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts. |
| ☐ | SV-283681r1204071_rule | The Nokia layer 2 switch must have Spanning Tree Protocol (STP) loop guard enabled on all nondesignated STP switch ports. |
| ☐ | SV-283682r1204074_rule | The Nokia layer 2 switch must have Unknown Unicast Flood Blocking (UUFB) enabled. |
| ☐ | SV-283683r1204077_rule | The Nokia layer 2 switch must have Dynamic Host Configuration Protocol (DHCP) snooping for all user virtual local area networks (VLANs) to validate DHCP messages from untrusted sources. |
| ☐ | SV-283684r1204128_rule | The Nokia layer 2 switch must provide source Internet Protocol (IP) address filtering on untrusted layer 2 interfaces. |
| ☐ | SV-283685r1204130_rule | The Nokia layer 2 switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user virtual local area networks (VLANs). |
| ☐ | SV-283686r1204132_rule | The Nokia layer 2 switch must have Storm Control configured on all host-facing switch ports. |
| ☐ | SV-283687r1204134_rule | The Nokia layer 2 switch must have Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) snooping configured on all virtual local area networks (VLANs). |
| ☐ | SV-283688r1204092_rule | The Nokia layer 2 switch must implement Rapid Spanning Tree Protocol (RSTP) where virtual local area networks (VLANs) span multiple switches with redundant links. |
| ☐ | SV-283689r1204095_rule | The Nokia layer 2 switch must enable Ethernet Connectivity Fault Management (ETH-CFM) to protect against one-way connections. |
| ☐ | SV-283690r1204098_rule | The Nokia layer 2 switch must assign all virtual private local area network service (VPLS) ports not in use to an inactive VLAN. |
| ☐ | SV-283691r1204101_rule | The Nokia layer 2 switch must not have the default virtual local area network (VLAN) assigned to any host-facing switch ports. |
| ☐ | SV-283692r1204104_rule | The Nokia layer 2 switch must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions. |