Skip to content

The Arista Multilayer Switch must be configured so inactive router interfaces are disabled.

An XCCDF Rule

Description

An inactive interface is rarely monitored or controlled and may expose a network to an undetected attack on that interface. Unauthorized personnel with access to the communication facility could gain access to a router by connecting to a configured interface that is not in use.

ID
SV-75353r1_rule
Version
AMLS-L3-000140
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Remove subinterfaces and disable any inactive ports on the router via the "shutdown" command on the interface configuration mode.