NET-VLAN-005 - VLAN 1 traffic traverses across unnecessary trunk

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The IAO/NSO will ensure VLAN1 is pruned from all trunk and access ports that do not require it.

VLAN 1 is a special VLAN that tags and handles most of the control plane traffic such as Spanning-Tree Protocol (STP), Cisco Discovery Protocol (CDP), Dynamic Trunking Protocol (DTP), VLAN Trunking Protocol (VTP), and Port Aggregation Protocol (PAgP)all VLAN 1 tagged traffic. VLAN 1 is enabled on all trunks and ports by default. With larger campus networks, care needs to be taken about the diameter of the VLAN 1 STP domain; instability in one part of the network could affect VLAN 1, thereby influencing control-plane stability and therefore STP stability for all other VLANs.

NOTE: This check is derived from the L3 switch guidance, if the scan target is a router the check can be ignored.
NOTE: This check requires manual verification to review the switch configuration and note any ports assigned to VLAN1. A show vlan command can also be used to verify what ports are assigned to VLAN1.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Best practice for VLAN-based networks is to prune unnecessary ports from gaining access to VLAN1 and insure that it does not traverse trunks not requiring VLAN1 traffic.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

References: CAT|III, Rule-ID|SV-3972r2_rule, STIG-ID|NET-VLAN-005, Vuln-ID|V-3972

Plugin: Cisco

Control ID: 298332ae2ccef1a449a6e3a086ef1d71a26531523aa5fa9c96b3bf4997b416ec