SV-80555r1_rule
V-66065
SRG-NET-000362-L2S-000022
HFFS-L2-000011
CAT II
10
Configure the HP FlexFabric Switch to have BPDU Guard enabled on all user-facing switch ports.
[HP]stp bpdu-protection
[HP-GigabitEthernet1/0/1]stp edged-port
Review the HP FlexFabric Switch configuration to verify that BPDU Protection is enabled on all user-facing switch ports.
If the HP FlexFabric Switch has not enabled BPDU protection, this is a finding.
[HP] display stp
-------[CIST Global Info][Mode MSTP]-------
Bridge ID : 32768.7848-596a-6580
Bridge times : Hello 2s MaxAge 20s FwdDelay 15s MaxHops 20
Root ID/ERPC : 32768.7848-596a-6580, 0
RegRoot ID/IRPC : 32768.7848-596a-6580, 0
RootPort ID : 0.0
BPDU-Protection : Enabled
Bridge Config-
Digest-Snooping : Disabled
TC or TCN received : 0
Time since last TC : 3 days
interface GigabitEthernet1/0/1
stp edged-port
V-66065
False
HFFS-L2-000011
Review the HP FlexFabric Switch configuration to verify that BPDU Protection is enabled on all user-facing switch ports.
If the HP FlexFabric Switch has not enabled BPDU protection, this is a finding.
[HP] display stp
-------[CIST Global Info][Mode MSTP]-------
Bridge ID : 32768.7848-596a-6580
Bridge times : Hello 2s MaxAge 20s FwdDelay 15s MaxHops 20
Root ID/ERPC : 32768.7848-596a-6580, 0
RegRoot ID/IRPC : 32768.7848-596a-6580, 0
RootPort ID : 0.0
BPDU-Protection : Enabled
Bridge Config-
Digest-Snooping : Disabled
TC or TCN received : 0
Time since last TC : 3 days
interface GigabitEthernet1/0/1
stp edged-port
M
2977