STIGUI
V-286561CAT II — Medium severitySV-286561r1274099_rule

The Aviat WTM must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.

Rule version AWTM-L2-000015 · STIG v1 · 2026-09-15

Discussion

Separating critical system components and functions from other noncritical system components and functions through separate subnetworks may be necessary to reduce susceptibility to a catastrophic or debilitating breach or compromise that results in system failure. For example, physically separating the command and control function from the in-flight entertainment function through separate subnetworks in a commercial aircraft provides an increased level of assurance in the trustworthiness of critical system functions.

This requirement also applies to Zero Trust initiatives.

Check

Verify the Aviat WTM implements separate management and data plane interfaces with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to System Configuration >> Management IP. 3. Verify that one GigabitEthernet interface (GigabitEthernet1/1 or GigabitEthernet1/2) is configured as the management interface. 4. Navigate to Switching and Routing >> VLAN Management >> Membership. 5. Verify the remaining GigabitEthernet interface and all TenGigE interfaces (TenGigE1/1 and TenGigE1/2) are configured as data plane interfaces and are not assigned to the management VLAN.

If a dedicated management interface is not configured separately from data plane interfaces, this is a finding.

Fix

Configure the Aviat WTM to implement separate management and data plane interfaces with the following steps:

1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> VLAN Management >> Define and create a dedicated management VLAN if one does not already exist. 3. Navigate to System Configuration >> Management IP. 4. Click "ADD", select one GigabitEthernet interface (GigabitEthernet1/1 or GigabitEthernet1/2), assign it to the management VLAN, and click "Commit". 5. Navigate to Switching and Routing >> VLAN Management >> Membership. 6. Verify the remaining GigabitEthernet interface and all TenGigE interfaces (TenGigE1/1 and TenGigE1/2) are assigned only to data plane VLANs. 7. Click "Commit".

Identifiers

Group ID
V-286561
Group title
SRG-NET-000715-L2S-000120
Rule ID
SV-286561r1274099_rule
Check ID
C-91243r1273962_chk
Fix ID
F-91148r1273963_fix