2.1.3 Disable Unused Physical Interfaces

Information

Disable unused physical interfaces.

Unused physical interfaces could allow an attacker to plug in a network cable and access network resources (depending on the configuration of that port).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Disable unused physical interfaces

switch# conf
switch(config)# interface 1/1/1
switch(config-if)# shutdown
switch(config-if)#

Impact:

Disabling unused physical interfaces helps to:

- Reduce the attack surface by minimizing open entry points, thus reducing pathways for attackers to access your network.
- Prevent unauthorized network access.
- Ensure compliance with many regulatory standards that require only necessary network ports to be active to maintain a secure environment.
- Improve network hygiene by regularly managing and configuring port settings.
- Enhance incident response by making it easier to isolate and respond effectively to security breaches with fewer active ports.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-7, 800-53|SC-4, CSCv7|14.1, CSCv7|14.7

Plugin: ArubaOS

Control ID: 72ffff39b8985c2a4b6fe982a93ad153cc4f31ae7df6fd5d64fca40fd03e8d40