Skip to content

SEL-2740S L2S Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The SEL-2740S must be configured with backup flows for all host and switch flows to ensure proper failover scheme is in place for the network.

    The SEL-2740S must be capable of multiple fast failover, backup and in cases isolation of the traffic from a detected threat in the system.
    Rule Medium Severity
  • SRG-NET-000512-L2S-000031

    Group
  • The SEL-2740S must be configured to forward only frames from allowed network-connected endpoint devices.

    By only allowing frames to be forwarded from known end-points mitigates risks associated with broadcast, unknown unicast, and multicast traffic storms.
    Rule Medium Severity
  • SRG-NET-000131-L2S-000014

    Group
  • SRG-NET-000512-L2S-000028

    Group
  • The SEL-2740S must be configured with ARP flow rules that are statically created with valid IP-to-MAC address bindings.

    DAI intercepts Address Resolution Protocol (ARP) requests and verifies that each of these packets has a valid IP-to-MAC address binding before updating the local ARP cache and before forwarding the...
    Rule Medium Severity
  • SRG-NET-000343-L2S-000016

    Group
  • SRG-NET-000331-L2S-000001

    Group
  • The SEL-2740S must be configured to packet capture flows.

    Without the capability to select a user session to capture/record or view/hear, investigations into suspicious or harmful events would be hampered by the volume of information captured. The volume ...
    Rule Medium Severity
  • SRG-NET-000332-L2S-000002

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules