UCF STIG Viewer Logo

The Arista Multilayer Switch must be configured so inactive router interfaces are disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-60895 AMLS-L3-000140 SV-75353r1_rule Medium
Description
An inactive interface is rarely monitored or controlled and may expose a network to an undetected attack on that interface. Unauthorized personnel with access to the communication facility could gain access to a router by connecting to a configured interface that is not in use.
STIG Date
Arista MLS DCS-7000 Series RTR Security Technical Implementation Guide 2020-06-02

Details

Check Text ( C-61843r1_chk )
Verify inactive interfaces on the router are disabled by executing a "show interface status" command and confirming the line "disabled" is present on any interface where the interface is inactive.

If there are any inactive interfaces enabled on the router, this is a finding.
Fix Text (F-66607r1_fix)
Remove subinterfaces and disable any inactive ports on the router via the "shutdown" command on the interface configuration mode.