STIGUI
V-286556CAT II — Medium severitySV-286556r1274094_rule

The Aviat WTM must not use the default VLAN for management traffic.

Rule version AWTM-L2-000010 · STIG v1 · 2026-09-15

Discussion

Switches use the default VLAN (i.e., VLAN 1) for in-band management and to communicate with directly connected switches using Spanning-Tree Protocol (STP), Dynamic Trunking Protocol (DTP), VLAN Trunking Protocol (VTP), and Port Aggregation Protocol (PAgP)—all untagged traffic. As a consequence, the default VLAN may unwisely span the entire network if not appropriately pruned. If its scope is large enough, the risk of compromise can increase significantly.

Check

Verify the Aviat WTM does not use the default VLAN (VLAN 1) for management traffic with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. For each management port, verify the access VLAN is not set to VLAN 1.

If any management port is assigned to VLAN 1, this is a finding.

Fix

Configure the Aviat WTM to remove VLAN 1 from all management ports with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. For each management port assigned to VLAN 1, change the access VLAN to the management VLAN. 4. Click "Commit".

Identifiers

Group ID
V-286556
Group title
SRG-NET-000512-L2S-000010
Rule ID
SV-286556r1274094_rule
Check ID
C-91238r1273947_chk
Fix ID
F-91143r1273948_fix