SV-220630r539671_rule
V-220630
SRG-NET-000362-L2S-000022
CISC-L2-000100
CAT II
10
Enable BPDU Guard on all user-facing or untrusted access switch ports as shown in the configuration example below:
SW1(config)#int range g0/0 - 9
SW1(config-if-range)#spanning-tree bpduguard enable
Note: BPDU Guard can also be enabled globally on all Port Fast-enabled ports by using the spanning-tree portfast bpduguard default command.
Review the switch configuration to verify that BPDU Guard is enabled on all user-facing or untrusted access switch ports as shown in the configuration example below:
interface GigabitEthernet0/0
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
spanning-tree bpduguard enable
…
…
…
interface GigabitEthernet0/9
spanning-tree bpduguard enable
If the switch has not enabled BPDU Guard, this is a finding.
V-220630
False
CISC-L2-000100
Review the switch configuration to verify that BPDU Guard is enabled on all user-facing or untrusted access switch ports as shown in the configuration example below:
interface GigabitEthernet0/0
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
spanning-tree bpduguard enable
…
…
…
interface GigabitEthernet0/9
spanning-tree bpduguard enable
If the switch has not enabled BPDU Guard, this is a finding.
M
4070