Rule version AWTM-L2-000003 · STIG v1 · 2026-09-15
If a rogue switch is introduced into the topology and transmits a BPDU with a lower bridge priority than the existing root bridge, it will become the new root bridge and cause a topology change, rendering the network in a suboptimal state. The Spanning Tree Protocol (STP) PortFast BPDU guard enhancement allows network designers to enforce the STP domain borders and keep the active topology predictable. The devices behind the ports that have STP PortFast enabled are not able to influence the STP topology. At the reception of BPDUs, the BPDU guard operation disables the port that has PortFast configured. The BPDU guard transitions the port into errdisable state and sends a log message.
Verify the Aviat WTM has BPDU Guard enabled on all user-facing or untrusted access switch ports with the following steps:
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> Spanning Tree. 3. Review the Interfaces table and verify "Port Fast" is selected for each user-facing or untrusted access port. 4. Verify BPDU Guard is selected for each user-facing or untrusted access port.
If the Port Fast or BPDU Guard checkbox is not selected for all user-facing or untrusted access switch ports, this is a finding.
Configure the Aviat WTM to enable BPDU Guard on all user-facing or untrusted access switch ports with the following steps:
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> Spanning Tree. 3. In the Interfaces table, select "Port Fast" for each user-facing or untrusted access port. 4. Select "BPDU Guard" for each user-facing or untrusted access port. 5. Click "Commit".