NET-VLAN-002 - Disabled ports are not kept in an unused VLAN.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The IAO/NSO will ensure disabled ports are placed in an unused VLAN (do not use VLAN1).

It is possible that a disabled port that is assigned to a user or management VLAN becomes enabled by accident or by an attacker and as a result gains access to that VLAN as a member.

NOTE: This check is derived from the L3 switch guidance, if the scan target is a router the check can be ignored.
NOTE: This check requires manual verification that all ports not in use are assigned to the unused VLAN ID specific to your organization.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Assign all disabled ports to an unused VLAN. Do not use VLAN1.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

References: CAT|III, Rule-ID|SV-3973r2_rule, STIG-ID|NET-VLAN-002, Vuln-ID|V-3973

Plugin: Cisco

Control ID: ec7195a2fcf3067b00317006668722d46f6ad5dd7393b5b12304704e25cd43e7