Rule version AWTM-L2-000008 · STIG v1 · 2026-09-15
In a VLAN-based network, switches use the default VLAN (i.e., VLAN 1) for in-band management and to communicate with other networking devices using Spanning-Tree Protocol (STP), Dynamic Trunking Protocol (DTP), VLAN Trunking Protocol (VTP), and Port Aggregation Protocol (PAgP)—all untagged traffic. As a consequence, the default VLAN may unwisely span the entire network if not appropriately pruned. If its scope is large enough, the risk of compromise can increase significantly.
Verify the Aviat WTM does not have the default VLAN (VLAN 1) assigned to any host-facing switch ports with the following steps:
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. Based on the site's documented configuration plan, for each host-facing switch port, verify the access VLAN is not set to VLAN 1.
If any host-facing switch port is assigned to VLAN 1, this is a finding.
Configure the Aviat WTM to remove VLAN 1 from all host-facing switch ports with the following steps:
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. For each host-facing switch port assigned to VLAN 1, change the access VLAN to a nondefault VLAN. 4. Click "Commit".