JUEX-L2-000190 - The Juniper EX switch must be configured to assign all disabled access interfaces to an unused VLAN.

Information

It is possible that a disabled access interface that is assigned to a user or management VLAN becomes enabled by accident or by an attacker and as a result gains access to that VLAN as a member.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Disable all access interfaces not in use and assign to an inactive VLAN.

In this example, 'vlan_disabled' is the name given to the VLAN for unused interfaces. This VLAN name can be any legal name.

set vlans vlan_disabled vlan-id <VLAN ID>

set interfaces interface-range <name> member <interface name>
set interfaces interface-range <name> member-range <starting interface name> to <ending interface name>
set interfaces interface-range <name> disable
set interfaces interface-range <name> unit 0 family ethernet-switching vlan members vlan_disabled

set interfaces <interface name> disable
set interfaces <interface name> unit 0 family ethernet-switching vlan members vlan_disabled

Delete the unused VLAN from all trunked interfaces.

delete interfaces <trunked interface> unit 0 family ethernet-switching vlan members vlan_disabled

Note: Switch ports configured for 802.1x are exempt from this requirement.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_EX_Switches_Y24M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-253966r843931_rule, STIG-ID|JUEX-L2-000190, Vuln-ID|V-253966

Plugin: Juniper

Control ID: 7c42665ad7cf02b3ec35fd3282c25dcc83cf19978ad683cf026255f0026bafbe