NET-SRVFRM-004 – ACLs do not protect against compromised servers Details The IAO will ensure the Server Farm infrastructure is secured by ACLs on VLAN interfaces that restrict data originating...
NET-TUNL-012 – Tunnel Default Router Configured Details http://www.cisco.com/c/en/us/td/docs/ios/12_2/qos/configuration/guide/fqos_c/qcfpbr.html Solution The SA must carefully plan and configure or let IGP determine what goes into each tunnel. Supportive...
NET-TUNL-017 – ISATAP tunnels must terminate at interior router Details ISATAP tunnels must terminate at an interior router. ISATAP is an automatic tunnel mechanism that does not provide authentication...
NET-VLAN-002 – Disabled ports are not kept in an unused VLAN. Details The IAO/NSO will ensure disabled ports are placed in an unused VLAN (do not use VLAN1). It is possible...
NET-VLAN-004 – VLAN 1 is being used as a user VLAN – ‘no ip address’. Details The IAO/NSO will ensure VLAN1 is not used for user VLANs. In a VLAN-based network, switches use VLAN1 as...
NET-VLAN-004 – VLAN 1 is being used as a user VLAN – ‘shutdown’. Details The IAO/NSO will ensure VLAN1 is not used for user VLANs. In a VLAN-based network, switches use VLAN1 as...
NET-VLAN-005 – VLAN 1 traffic traverses across unnecessary trunk Details The IAO/NSO will ensure VLAN1 is pruned from all trunk and access ports that do not require it. VLAN...
NET-VLAN-006 – The VLAN1 is being used for management traffic. Details The IAO/NSO will ensure VLAN1 is not used for in-band management traffic. A dedicated management VLAN or VLANs will...
NET-VLAN-007 – Ensure trunking is disabled on all access ports. Details The IAO/NSO will ensure trunking is disabled on all access ports (do not configure trunk on, desirable, non-negotiate, or...
NET-VLAN-008 – A dedicated VLAN is required for all trunk ports. Details The IAS/NSO will ensure that the native VLAN is assigned to a VLAN ID other than the default VLAN...