NET-NAC-032 - Switchport does not shutdown on a violation

Information

The IAO will ensure that all switchports configured using MAC port security will shutdown upon receiving a frame with a different layer 2 source address than what has been configured or learned for port security.

The Port Security feature remembers the Ethernet MAC address connected to the switch port and allows only that MAC address to communicate on that port. If any other MAC address tries to communicate through the port, port security will disable the port.

NOTE: This check is derived from the L3 switch guidance, if the scan target is a router the check can be ignored.

Solution

Configure the port to shutdown when insecure hosts are connected to the wall jack.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(7), CAT|III, Rule-ID|SV-20109r1_rule, STIG-ID|NET-NAC-032, Vuln-ID|V-18565

Plugin: Cisco

Control ID: c36facdf9d291c730880abece261ee08919232f19e3dedc43bc290defdf4a95c