Check: AMLS-L3-000140
Arista MLS DCS-7000 Series RTR STIG:
AMLS-L3-000140
(in versions v1 r3 through v1 r2)
Title
The Arista Multilayer Switch must be configured so inactive router interfaces are disabled. (Cat II impact)
Discussion
An inactive interface is rarely monitored or controlled and may expose a network to an undetected attack on that interface. Unauthorized personnel with access to the communication facility could gain access to a router by connecting to a configured interface that is not in use.
Check Content
Verify inactive interfaces on the router are disabled by executing a "show interface status" command and confirming the line "disabled" is present on any interface where the interface is inactive. If there are any inactive interfaces enabled on the router, this is a finding.
Fix Text
Remove subinterfaces and disable any inactive ports on the router via the "shutdown" command on the interface configuration mode.
Additional Identifiers
Rule ID: SV-75353r1_rule
Vulnerability ID: V-60895
Group Title: SRG-NET-000019-RTR-000007
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001414 |
The information system enforces approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies. |
Controls
Number | Title |
---|---|
AC-4 |
Information Flow Enforcement |