SV-110345r1_rule
V-101241
SRG-NET-000362-L2S-000026
CISC-L2-000140
CAT II
10
Configure the switch to have IP Source Guard enabled on all user-facing or untrusted access switch ports.
SW1(config)# int e1/1-32
SW1(config-if-range)# ip verify source dhcp-snooping-vlan
Review the switch configuration to verify that IP Source Guard is enabled on all user-facing or untrusted access switch ports as shown in the example below:
interface Ethernet1/1
ip verify source dhcp-snooping-vlan
interface Ethernet1/2
ip verify source dhcp-snooping-vlan
…
…
…
interface Ethernet1/32
ip verify source dhcp-snooping-vlan
Note: the IP Source Guard feature depends on the entries in the DHCP snooping database or static IP-MAC-VLAN configuration commands to verify IP-to-MAC address bindings.
If the switch does not have IP Source Guard enabled on all untrusted access switch ports, this is a finding.
V-101241
False
CISC-L2-000140
Review the switch configuration to verify that IP Source Guard is enabled on all user-facing or untrusted access switch ports as shown in the example below:
interface Ethernet1/1
ip verify source dhcp-snooping-vlan
interface Ethernet1/2
ip verify source dhcp-snooping-vlan
…
…
…
interface Ethernet1/32
ip verify source dhcp-snooping-vlan
Note: the IP Source Guard feature depends on the entries in the DHCP snooping database or static IP-MAC-VLAN configuration commands to verify IP-to-MAC address bindings.
If the switch does not have IP Source Guard enabled on all untrusted access switch ports, this is a finding.
M
3551