JUEX-L2-000180 - The Juniper EX switch must be configured to verify two-way connectivity on all interswitch trunked interfaces.

Information

In topologies where fiber optic interconnections are used, physical misconnections can occur that allow a link to appear to be up when there is a mismatched set of transmit/receive pairs. When such a physical misconfiguration occurs, protocols such as STP can cause network instability. OAM LFM and LAG are industry standard layer 2 protocols that can detect these physical misconfigurations by verifying that traffic is flowing bidirectionally between neighbors. Interfaces with OAM configured, and LAG interfaces, periodically transmit packets to neighbor devices. If the packets are not exchanged within a specific time frame, the link is flagged as unidirectional and the interface is shut down. OAM LFM and LAG require both connected devices to be configured.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the switch to enable OAM or LAG to protect against one-way connections.

LFM with default values:
set protocols oam ethernet link-fault-management interface <interface name>

LAG:
set interfaces <interface name> ether-options 802.3ad ae<bundle number>

set interfaces ae<bundle number> aggregated-ether-options lacp
set interfaces ae<bundle number> unit 0 family ethernet-switching interface-mode trunk
set interfaces ae<bundle number> unit 0 family ethernet-switching vlan members <vlan_name>
:
set interfaces ae<bundle number> unit 0 family ethernet-switching vlan members <vlan_name>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_EX_Switches_Y24M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-253965r843928_rule, STIG-ID|JUEX-L2-000180, Vuln-ID|V-253965

Plugin: Juniper

Control ID: 5668fb3758f6300181127527c4eed8e711698913a491d09e05332a69eb0ac21b