DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5

Audit Details

Name: DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5

Updated: 9/18/2026

Authority: DISA STIG

Plugin: Juniper

Revision: 1.0

Estimated Item Count: 24

File Details

Filename: DISA_STIG_Juniper_EX_Series_Switches_Layer_2_Switch_v2r5.audit

Size: 64.9 kB

MD5: cd8334140886878d8b04cbc5e66d378b
SHA256: a4052046fb0089d059f5c732524bb74dbce2667602258c478f5f8cc0b167dc24

Audit Items

DescriptionCategories
JUEX-L2-000010 - The Juniper EX switch must be configured to disable non-essential capabilities.

CONFIGURATION MANAGEMENT

JUEX-L2-000020 - The Juniper EX switch must be configured to uniquely identify all network-connected endpoint devices before establishing any connection.

IDENTIFICATION AND AUTHENTICATION

JUEX-L2-000030 - The Juniper layer 2 switch must be configured to disable all dynamic VLAN registration protocols.

IDENTIFICATION AND AUTHENTICATION

JUEX-L2-000040 - The Juniper EX switch must be configured to manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000050 - The Juniper EX switch must be configured to permit authorized users to select a user session to capture.

AUDIT AND ACCOUNTABILITY

JUEX-L2-000060 - The Juniper EX switch must be configured to permit authorized users to remotely view, in real time, all content related to an established user session from a component separate from the layer 2 switch.

AUDIT AND ACCOUNTABILITY

JUEX-L2-000070 - The Juniper EX switch must be configured to authenticate all network-connected endpoint devices before establishing any connection.

IDENTIFICATION AND AUTHENTICATION

JUEX-L2-000080 - The Juniper EX switch must be configured to enable Root Protection on STP switch ports connecting to access layer switches.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000090 - The Juniper EX switch must be configured to enable BPDU Protection on all user-facing or untrusted access switch ports.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000100 - The Juniper EX switch must be configured to enable STP Loop Protection on all non-designated STP switch ports.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000120 - The Juniper EX switch must be configured to enable DHCP snooping for all user VLANs with active access interfaces to validate DHCP messages from untrusted sources.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000130 - The Juniper EX switch must be configured to enable IP Source Guard on all user-facing or untrusted access VLANs with active access interfaces.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000140 - The Juniper EX switch must be configured to enable Dynamic Address Resolution Protocol (ARP) Inspection (DAI) on all user VLANs with active access interfaces.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000150 - The Juniper EX switch must be configured to enable Storm Control on all host-facing access interfaces.

CONFIGURATION MANAGEMENT

JUEX-L2-000160 - The Juniper EX switch must be configured to enable IGMP or MLD Snooping on all VLANs.

CONFIGURATION MANAGEMENT

JUEX-L2-000170 - If STP is used, the Juniper EX switch must be configured to implement Rapid STP, or Multiple STP, where VLANs span multiple switches with redundant links.

CONFIGURATION MANAGEMENT

JUEX-L2-000180 - The Juniper EX switch must be configured to verify two-way connectivity on all interswitch trunked interfaces.

CONFIGURATION MANAGEMENT

JUEX-L2-000190 - The Juniper EX switch must be configured to assign all explicitly disabled access interfaces to an unused VLAN.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000200 - The Juniper EX switch must not be configured with VLANs used for L2 control traffic assigned to any host-facing access interface.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000210 - The Juniper EX switch must be configured to prune the default VLAN from all trunked interfaces that do not require it.

CONFIGURATION MANAGEMENT

JUEX-L2-000220 - The Juniper EX switch must not use the default VLAN for management traffic.

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000230 - The Juniper EX switch must be configured to set all enabled user-facing or untrusted ports as access interfaces.

CONFIGURATION MANAGEMENT

JUEX-L2-000240 - The Juniper EX switch must not have a native VLAN ID assigned, or have a unique native VLAN ID, for all 802.1q trunk links.

CONFIGURATION MANAGEMENT

JUEX-L2-000250 - The Juniper EX switch must not have any access interfaces assigned to a VLAN configured as native for any trunked interface.

CONFIGURATION MANAGEMENT