STIGUI
V-286554CAT II — Medium severitySV-286554r1274092_rule

The Aviat WTM must not have the default VLAN assigned to any host-facing switch ports.

Rule version AWTM-L2-000008 · STIG v1 · 2026-09-15

Discussion

In a VLAN-based network, switches use the default VLAN (i.e., VLAN 1) for in-band management and to communicate with other networking devices using Spanning-Tree Protocol (STP), Dynamic Trunking Protocol (DTP), VLAN Trunking Protocol (VTP), and Port Aggregation Protocol (PAgP)—all untagged traffic. As a consequence, the default VLAN may unwisely span the entire network if not appropriately pruned. If its scope is large enough, the risk of compromise can increase significantly.

Check

Verify the Aviat WTM does not have the default VLAN (VLAN 1) assigned to any host-facing switch ports with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. Based on the site's documented configuration plan, for each host-facing switch port, verify the access VLAN is not set to VLAN 1.

If any host-facing switch port is assigned to VLAN 1, this is a finding.

Fix

Configure the Aviat WTM to remove VLAN 1 from all host-facing switch ports with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. For each host-facing switch port assigned to VLAN 1, change the access VLAN to a nondefault VLAN. 4. Click "Commit".

Identifiers

Group ID
V-286554
Group title
SRG-NET-000512-L2S-000008
Rule ID
SV-286554r1274092_rule
Check ID
C-91236r1273941_chk
Fix ID
F-91141r1273942_fix