JUEX-L2-000150 - The Juniper EX switch must be configured to enable Storm Control on all host-facing access interfaces.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A traffic storm occurs when packets flood a LAN, creating excessive traffic and degrading network performance. Traffic storm control prevents network disruption by suppressing ingress traffic when the number of packets reaches configured threshold levels. Traffic storm control monitors ingress traffic levels on a port and drops traffic when the number of packets reaches the configured threshold level during any one-second interval.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure storm control on each host-facing access interface.

set forwarding-options storm-control-profiles profile-percent all bandwidth-percentage (1..100)
set forwarding-options storm-control-profiles profile-level all bandwidth-level (100..100000000 kbps)

set interfaces <interface name> unit 0 family ethernet-switching storm-control <profile name>
set interfaces <interface name> unit 0 family ethernet-switching recovery-timeout (10..3600 seconds)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_EX_Switches_Y24M01_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Rule-ID|SV-253962r843919_rule, STIG-ID|JUEX-L2-000150, Vuln-ID|V-253962

Plugin: Juniper

Control ID: 48bf321b44f3c554d376ff7c112b93f4696413555aadc8e6270243c1c073772d