STIGUI
V-286550CAT II — Medium severitySV-286550r1274088_rule

The Aviat WTM must have Bridge Protocol Data Unit (BPDU) Guard enabled on all user-facing or untrusted access switch ports.

Rule version AWTM-L2-000003 · STIG v1 · 2026-09-15

Discussion

If a rogue switch is introduced into the topology and transmits a BPDU with a lower bridge priority than the existing root bridge, it will become the new root bridge and cause a topology change, rendering the network in a suboptimal state. The Spanning Tree Protocol (STP) PortFast BPDU guard enhancement allows network designers to enforce the STP domain borders and keep the active topology predictable. The devices behind the ports that have STP PortFast enabled are not able to influence the STP topology. At the reception of BPDUs, the BPDU guard operation disables the port that has PortFast configured. The BPDU guard transitions the port into errdisable state and sends a log message.

Check

Verify the Aviat WTM has BPDU Guard enabled on all user-facing or untrusted access switch ports with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> Spanning Tree. 3. Review the Interfaces table and verify "Port Fast" is selected for each user-facing or untrusted access port. 4. Verify BPDU Guard is selected for each user-facing or untrusted access port.

If the Port Fast or BPDU Guard checkbox is not selected for all user-facing or untrusted access switch ports, this is a finding.

Fix

Configure the Aviat WTM to enable BPDU Guard on all user-facing or untrusted access switch ports with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> Spanning Tree. 3. In the Interfaces table, select "Port Fast" for each user-facing or untrusted access port. 4. Select "BPDU Guard" for each user-facing or untrusted access port. 5. Click "Commit".

Identifiers

Group ID
V-286550
Group title
SRG-NET-000362-L2S-000022
Rule ID
SV-286550r1274088_rule
Check ID
C-91232r1274042_chk
Fix ID
F-91137r1274043_fix