SV-110359r1_rule
V-101255
SRG-NET-000512-L2S-000009
CISC-L2-000230
CAT II
10
Step 1: Prune VLAN 1 from any trunk links as necessary.
SW1(config)# int e1/2
SW1(config-if)# switchport trunk allowed vlan except 1, 999
SW1(config-if)# end
Step 2: Verify VLAN 1 is not allowed on the trunk link.
SW1# show interface trunk
--------------------------------------------------------------------------------
Port Native Status Port
Vlan Channel
--------------------------------------------------------------------------------
Eth1/1 1 trunking --
Eth1/2 1 trunking --
--------------------------------------------------------------------------------
Port Vlans Allowed on Trunk
--------------------------------------------------------------------------------
Eth1/1 1-998,1000-4094
Eth1/2 2-998,1000-4094
Review the switch configuration and verify that the default VLAN is pruned from trunk links that do not require it.
SW1# show interface trunk
--------------------------------------------------------------------------------
Port Native Status Port
Vlan Channel
--------------------------------------------------------------------------------
Eth1/1 1 trunking --
Eth1/2 1 trunking --
--------------------------------------------------------------------------------
Port Vlans Allowed on Trunk
--------------------------------------------------------------------------------
Eth1/1 1-998,1000-4094
Eth1/2 1-998,1000-4094
If the default VLAN is not pruned from trunk links that should not be transporting frames for the VLAN, this is a finding.
V-101255
False
CISC-L2-000230
Review the switch configuration and verify that the default VLAN is pruned from trunk links that do not require it.
SW1# show interface trunk
--------------------------------------------------------------------------------
Port Native Status Port
Vlan Channel
--------------------------------------------------------------------------------
Eth1/1 1 trunking --
Eth1/2 1 trunking --
--------------------------------------------------------------------------------
Port Vlans Allowed on Trunk
--------------------------------------------------------------------------------
Eth1/1 1-998,1000-4094
Eth1/2 1-998,1000-4094
If the default VLAN is not pruned from trunk links that should not be transporting frames for the VLAN, this is a finding.
M
3551