SV-110335r1_rule
V-101231
SRG-NET-000362-L2S-000021
CISC-L2-000090
CAT III
10
Configure the switch to have Root Guard enabled on all ports connecting to access layer switches and hosts.
SW1(config)# int e1/1 – 44
SW1(config-if-range)# spanning-tree guard root
SW1(config-if-range)# end
Review the switch topology as well as the configuration to verify that Root Guard is enabled on all switch ports connecting to access layer switches and hosts.
interface Ethernet1/1
…
…
…
spanning-tree guard root
interface Ethernet1/2
…
…
…
spanning-tree guard root
interface Ethernet1/3
…
…
…
spanning-tree guard root
If the switch has not enabled Root Guard on all switch ports connecting to access layer switches and hosts, this is a finding.
V-101231
False
CISC-L2-000090
Review the switch topology as well as the configuration to verify that Root Guard is enabled on all switch ports connecting to access layer switches and hosts.
interface Ethernet1/1
…
…
…
spanning-tree guard root
interface Ethernet1/2
…
…
…
spanning-tree guard root
interface Ethernet1/3
…
…
…
spanning-tree guard root
If the switch has not enabled Root Guard on all switch ports connecting to access layer switches and hosts, this is a finding.
M
3551