NET1003 - Mgmt VLAN does not have correct IP address

Information

The management VLAN is not configured with an IP address from the management network address block.

If the management systems reside within the same layer 2 switching domain as the managed network elements, then separate VLANs will be deployed to provide separation at that level. In this case, the management network still has its own subnet while at the same time it is defined as a unique VLAN.

NOTE: This check is derived from the L3 switch guidance, if the scan target is a router the check can be ignored.
NOTE: This check requires manual verification that the IP address assigned is a part of the management network address range.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the management VLAN with an IP address from the management network address block.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R28_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-19702r1_rule, STIG-ID|NET1003, Vuln-ID|V-17832

Plugin: Cisco

Control ID: 919a41dc39ac40b883a75629a648565c99739b3431f28c95e120c8d02b6a91e4