STIGQter STIGQter: STIG Summary: Layer 2 Switch Security Requirements Guide Version: 1 Release: 6 Benchmark Date: 24 Jan 2020:

The layer 2 switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

DISA Rule

SV-76671r2_rule

Vulnerability Number

V-62181

Group Title

SRG-NET-000362

Rule Version

SRG-NET-000362-L2S-000025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the switch to have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.

Check Contents

Review the switch configuration and verify that DHCP snooping is enabled on all user VLANs.

If the switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Vulnerability Number

V-62181

Documentable

False

Rule Version

SRG-NET-000362-L2S-000025

Severity Override Guidance

Review the switch configuration and verify that DHCP snooping is enabled on all user VLANs.

If the switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources, this is a finding.

Check Content Reference

M

Target Key

2917

Comments