SV-220668r539671_rule
V-220668
SRG-NET-000512-L2S-000008
CISC-L2-000220
CAT II
10
Remove the assignment of the default VLAN from all access switch ports.
Review the switch configurations and verify that no access switch ports have been assigned membership to the default VLAN (i.e., VLAN 1). VLAN assignments can be verified via the show vlan command.
SW1#show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active
10 User VLAN active Gi0/3, Gi1/0, Gi1/1, Gi1/2
Gi1/3, Gi2/1
20 Management VLAN active Gi0/2
999 VLAN0999 active Gi2/0
If there are access switch ports assigned to the default VLAN, this is a finding.
V-220668
False
CISC-L2-000220
Review the switch configurations and verify that no access switch ports have been assigned membership to the default VLAN (i.e., VLAN 1). VLAN assignments can be verified via the show vlan command.
SW1#show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active
10 User VLAN active Gi0/3, Gi1/0, Gi1/1, Gi1/2
Gi1/3, Gi2/1
20 Management VLAN active Gi0/2
999 VLAN0999 active Gi2/0
If there are access switch ports assigned to the default VLAN, this is a finding.
M
4071