STIGUI
V-286551CAT II — Medium severitySV-286551r1274266_rule

The Aviat WTM must have Spanning Tree Protocol (STP) Loop Guard enabled on all nondesignated STP switch ports.

Rule version AWTM-L2-000004 · STIG v1 · 2026-09-15

Discussion

The STP loop guard feature provides additional protection against STP loops. An STP loop is created when an STP blocking port in a redundant topology erroneously transitions to the forwarding state. In its operation, STP relies on continuous reception and transmission of BPDUs based on the port role. The designated port transmits BPDUs, and the nondesignated port receives BPDUs. When one of the ports in a physically redundant topology no longer receives BPDUs, the STP conceives that the topology is loop free. Eventually, the blocking port from the alternate or backup port becomes a designated port and moves to a forwarding state. This situation creates a loop. The loop guard feature makes additional checks. If BPDUs are not received on a nondesignated port and loop guard is enabled, that port is moved into the STP loop-inconsistent blocking state.

Satisfies: SRG-NET-000362-L2S-000023, SRG-NET-000512-L2S-000003

Check

Verify the Aviat WTM has Rapid Spanning Tree Protocol (RSTP) enabled.

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> Spanning Tree. 3. Verify the "Mode" field is set to "RSTP".

If the "Mode" field is not set to "RSTP", this is a finding.

Fix

Configure the Aviat WTM to enable RSTP.

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> Spanning Tree. 3. In the "Mode" field, select "RSTP". 4. Click "Commit".

Identifiers

Group ID
V-286551
Group title
SRG-NET-000362-L2S-000023
Rule ID
SV-286551r1274266_rule
Check ID
C-91233r1274264_chk
Fix ID
F-91138r1274265_fix