OS10-RTR-000620 - The Dell OS10 Router must be configured to have Gratuitous ARP disabled on all external interfaces.

Information

A gratuitous ARP is an ARP broadcast in which the source and destination MAC addresses are the same. It is used to inform the network about a host IP address. A spoofed gratuitous ARP message can cause network mapping information to be stored incorrectly, causing network malfunction.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the Dell OS10 Switch to disable gratuitous arp on all external interfaces as shown in the example below:

OS10(config)# interface ethernet 1/1/1
OS10(conf-if-eth1/1/1)# no ip arp gratuitous update

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Dell_OS10_Switch_Y24M12_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, CAT|II, CCI|CCI-002385, Rule-ID|SV-269887r1052046_rule, STIG-ID|OS10-RTR-000620, Vuln-ID|V-269887

Plugin: Dell_OS10

Control ID: beb65e54cc56445aafc412ba7e0626b27f90a026917def005d574a86cdcc5e8c