OS10-L2S-000110 - The Dell OS10 Switch must have STP Loop Guard enabled on all nondesignated STP switch ports.

Information

The Spanning Tree Protocol (STP) loop guard feature provides additional protection against STP loops. An STP loop is created when an STP blocking port in a redundant topology erroneously transitions to the forwarding state. In its operation, STP relies on continuous reception and transmission of Bridge Protocol Data Unit (BPDUs) based on the port role. The designated port transmits BPDUs, and the nondesignated port receives BPDUs. When one of the ports in a physically redundant topology no longer receives BPDUs, the STP conceives that the topology is loop free. Eventually, the blocking port from the alternate or backup port becomes a designated port and moves to a forwarding state. This situation creates a loop. The loop guard feature makes additional checks. If BPDUs are not received on a nondesignated port and loop guard is enabled, that port is moved into the STP loop-inconsistent blocking state.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the switch to have STP Loop Guard enabled globally, or at a minimum, on all nondesignated STP switch ports.

OS10(config)# interface range ethernet 1/1/1-1/1/58
OS10(conf-range-eth1/1/1-1/1/58)# spanning-tree guard loop

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Dell_OS10_Switch_Y24M12_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, CAT|II, CCI|CCI-002385, Rule-ID|SV-269957r1052257_rule, STIG-ID|OS10-L2S-000110, Vuln-ID|V-269957

Plugin: Dell_OS10

Control ID: 51985810012101e7bc255932be70024af9ba49463250114e9e28f51834fb363e