STIGQter STIGQter: STIG Summary:

Nokia Service Router OS 25.x Layer 2 Switch Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 28 Apr 2026

CheckedNameTitle
SV-283678r1204062_ruleThe Nokia layer 2 switch must uniquely identify all network-connected endpoint devices before establishing any connection.
SV-283679r1204137_ruleThe Nokia layer 2 switch must manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks.
SV-283680r1204068_ruleThe Nokia layer 2 switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts.
SV-283681r1204071_ruleThe Nokia layer 2 switch must have Spanning Tree Protocol (STP) loop guard enabled on all nondesignated STP switch ports.
SV-283682r1204074_ruleThe Nokia layer 2 switch must have Unknown Unicast Flood Blocking (UUFB) enabled.
SV-283683r1204077_ruleThe Nokia layer 2 switch must have Dynamic Host Configuration Protocol (DHCP) snooping for all user virtual local area networks (VLANs) to validate DHCP messages from untrusted sources.
SV-283684r1204128_ruleThe Nokia layer 2 switch must provide source Internet Protocol (IP) address filtering on untrusted layer 2 interfaces.
SV-283685r1204130_ruleThe Nokia layer 2 switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user virtual local area networks (VLANs).
SV-283686r1204132_ruleThe Nokia layer 2 switch must have Storm Control configured on all host-facing switch ports.
SV-283687r1204134_ruleThe Nokia layer 2 switch must have Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) snooping configured on all virtual local area networks (VLANs).
SV-283688r1204092_ruleThe Nokia layer 2 switch must implement Rapid Spanning Tree Protocol (RSTP) where virtual local area networks (VLANs) span multiple switches with redundant links.
SV-283689r1204095_ruleThe Nokia layer 2 switch must enable Ethernet Connectivity Fault Management (ETH-CFM) to protect against one-way connections.
SV-283690r1204098_ruleThe Nokia layer 2 switch must assign all virtual private local area network service (VPLS) ports not in use to an inactive VLAN.
SV-283691r1204101_ruleThe Nokia layer 2 switch must not have the default virtual local area network (VLAN) assigned to any host-facing switch ports.
SV-283692r1204104_ruleThe Nokia layer 2 switch must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.