1. Home
  2. Security Hardening
  3. DISA STIG Cisco IOS Switch RTR V2R1
  4. CISC-RT-000150 – The Cisco switch must be configured to have gratuitous ARP disabled on all external interfaces.

CISC-RT-000150 – The Cisco switch must be configured to have gratuitous ARP disabled on all external interfaces.

Details

A gratuitous ARP is an ARP broadcast in which the source and destination MAC addresses are the same. It is used to inform the network about a host IP address. A spoofed gratuitous ARP message can cause network mapping information to be stored incorrectly, causing network malfunction.

Solution

Disable gratuitous ARP as shown in the example below:

SW1(config)#no ip gratuitous-arps

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Cisco.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles