JUEX-L2-000150 - The Juniper EX switch must be configured to enable Storm Control on all host-facing access interfaces.

Information

A traffic storm occurs when packets flood a LAN, creating excessive traffic and degrading network performance. Traffic storm control prevents network disruption by suppressing ingress traffic when the number of packets reaches configured threshold levels. Traffic storm control monitors ingress traffic levels on a port and drops traffic when the number of packets reaches the configured threshold level during any one-second interval.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure storm control on each host-facing access interface.

set forwarding-options storm-control-profiles profile-percent all bandwidth-percentage (1..100)
set forwarding-options storm-control-profiles profile-level all bandwidth-level (100..100000000 kbps)

set interfaces <interface name> unit 0 family ethernet-switching storm-control <profile name>
set interfaces <interface name> unit 0 family ethernet-switching recovery-timeout (10..3600 seconds)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_EX_Switches_Y24M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-253962r843919_rule, STIG-ID|JUEX-L2-000150, Vuln-ID|V-253962

Plugin: Juniper

Control ID: d68b4fb9a1f7477c4cd4ad3d4e58a0757fc95c41b5d5549a30713ef760230539