STIGUI
V-286558CAT II — Medium severitySV-286558r1274096_rule

The Aviat WTM must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.

Rule version AWTM-L2-000012 · STIG v1 · 2026-09-15

Discussion

VLAN hopping can be initiated by an attacker who has access to a switch port belonging to the same VLAN as the native VLAN of the trunk link connecting to another switch that the victim is connected to. If the attacker knows the victim's MAC address, it can forge a frame with two 802.1q tags and a layer 2 header with the destination address of the victim. Since the frame will ingress the switch from a port belonging to its native VLAN, the trunk port connecting to the victim's switch will simply remove the outer tag because native VLAN traffic is to be untagged. The switch will forward the frame on to the trunk link unaware of the inner tag with a VLAN ID of which the victim's switch port is a member.

Check

Verify the Aviat WTM has the native VLAN set to an ID other than VLAN 1 on all 802.1q trunk links with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Membership. 3. For each trunk port, verify the native (untagged) VLAN is not set to VLAN 1.

If the native VLAN on any trunk port is set to VLAN 1, this is a finding.

Fix

Configure the Aviat WTM to set the native VLAN to an ID other than VLAN 1 on all 802.1q trunk links with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Definition. 3. If a dedicated native VLAN does not already exist, click "ADD", enter a nondefault VLAN ID and name, and click "Commit". 4. Navigate to Switching and Routing >> VLAN Management >> Membership. 5. For each trunk port with a native VLAN of VLAN 1, change the native (untagged) VLAN to the newly created nondefault VLAN ID. 6. Click "Commit".

Identifiers

Group ID
V-286558
Group title
SRG-NET-000512-L2S-000012
Rule ID
SV-286558r1274096_rule
Check ID
C-91240r1273953_chk
Fix ID
F-91145r1273954_fix