AMLS-L3-000140 - Arista MLS must be configured so inactive router interfaces are disabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

An inactive interface is rarely monitored or controlled and may expose a network to an undetected attack on that interface. Unauthorized personnel with access to the communication facility could gain access to a router by connecting to a configured interface that is not in use.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remove subinterfaces and disable any inactive ports on the router via the 'shutdown' command on the interface configuration mode.

See Also

http://iasecontent.disa.mil/stigs/zip/Apr2016/U_Arista_MLS_DCS-7000_Series_RTR_V1R2_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(14), CAT|II, CCI|CCI-001414, Group-ID|V-60895, Rule-ID|SV-75353r1_rule, STIG-ID|AMLS-L3-000140

Plugin: Arista

Control ID: 9e8429a9ba68d8103bcde14ea5c6da8ca430c8299b0260195d559a2a442d5d62