OS10-L2S-000210 - The Dell OS10 Switch must have all disabled switch ports assigned to an unused VLAN.

Information

It is possible that a disabled port that is assigned to a user or management VLAN becomes enabled by accident or by an attacker and as a result gains access to that VLAN as a member.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Assign all switch ports not in use to an inactive VLAN.

Assign a VLAN interface to be unused:

OS10(config)# interface vlan 999
OS10(conf-if-vl-999)# description "Unused VLAN"
OS10(conf-if-vl-999)# shutdown
OS10(conf-if-vl-999)# exit

Assign unused switch ports to the unused VLAN:

OS10(config)# interface range eth1/1/50-1/1/58
OS10(conf-range-eth1/1/50-1/1/58)# switchport access vlan 999

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Dell_OS10_Switch_Y24M12_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-269966r1052284_rule, STIG-ID|OS10-L2S-000210, Vuln-ID|V-269966

Plugin: Dell_OS10

Control ID: 59a485dee819bf1ada3790685515e6d1f933f7fdc100f0ed594c4c59106d31a5