The SEL-2740S must be configured with backup flows for all host and switch flows to ensure proper failover scheme is in place for the network.
Overview
Finding ID | Version | Rule ID | IA Controls | Severity |
V-92281 | SELS-SW-000300 | SV-102369r1_rule | Medium |
Description |
The SEL-2740S must be capable of multiple fast failover, backup and in cases isolation of the traffic from a detected threat in the system. |
STIG | Date |
SEL-2740S L2S Security Technical Implementation Guide | 2019-05-06 |
Details
Check Text (C-91579r1_chk) |
Review the SEL-2740S flow rules to ensure each flow has a Fast Failover Group configured. If the switch is not configured to provide backup flows, this is a finding. |
Fix Text (F-98521r2_fix) |
To configure a Fast Failover Group for a given flow, do the following: 1. Log on to OTSDN Controller using Permission Level 3. 2. Under Group Entry General settings, select "Group ID" and "Group Type" as "Fast Failover". 3. Select appropriate number of Action Buckets dependent upon use case. 4. Determine valid watch port or group, and select supported actions. 5. Click "Submit". |