SV-220643r539671_rule
V-220643
SRG-NET-000512-L2S-000009
CISC-L2-000230
CAT II
10
Prune VLAN 1 from any trunk links as necessary:
SW1(config)#int g0/2
SW1(config-if)#switchport trunk allowed vlan except 1
Verify that VLAN 1 is not allowed on the trunk link:
SW1#show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 1
Gi0/2 on 802.1q trunking 1
Port Vlans allowed on trunk
Gi0/1 1-998,1000-4094
Gi0/2 2-4094
Review the switch configuration and verify that the default VLAN is pruned from trunk links that do not require it:
SW1#show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 1
Gi0/2 on 802.1q trunking 1
Port Vlans allowed on trunk
Gi0/1 1-998,1000-4094
Gi0/2 1-4094
If the default VLAN is not pruned from trunk links that should not be transporting frames for the VLAN, this is a finding.
V-220643
False
CISC-L2-000230
Review the switch configuration and verify that the default VLAN is pruned from trunk links that do not require it:
SW1#show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 1
Gi0/2 on 802.1q trunking 1
Port Vlans allowed on trunk
Gi0/1 1-998,1000-4094
Gi0/2 1-4094
If the default VLAN is not pruned from trunk links that should not be transporting frames for the VLAN, this is a finding.
M
4070