Skip to content

The Dell OS10 Switch must have all disabled switch ports assigned to an unused VLAN.

An XCCDF Rule

Description

It is possible that a disabled port that is assigned to a user or management VLAN becomes enabled by accident or by an attacker and as a result gains access to that VLAN as a member.

ID
SV-269966r1052284_rule
Version
OS10-L2S-000210
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Assign all switch ports not in use to an inactive VLAN.

Assign a VLAN interface to be unused:

OS10(config)# interface vlan 999
OS10(conf-if-vl-999)# description "Unused VLAN"