Rule version AWTM-L2-000027 · STIG v1 · 2026-09-15
Physical misconfiguration of network ports can cause network instability for protocols such as STP.
In topologies where fiber optic interconnections are used, physical misconnections can occur that allow a link to appear to be up when there is a mismatched set of transmit/receive pairs. Although more common in fiber connections, it can occur in misconfigured copper cables.
WTM implementations in DoW must have Link Aggregation Control Protocol (LACP) enabled and configured on uplink switch connections to enable layer 2 link aggregation with LACP in fast rate mode. LACP continuously exchanges PDUs between link partners and will detect a unidirectional link failure when the partner stops receiving LACP PDUs, removing the failed member from the Link Aggregation Group (LAG).
Note: This product does not provide UDLD (Cisco proprietary) or 802.ag protocols. It is recommended that the WTM is connected to an upstream switch that has one of these protections enabled on the connecting port. The upstream switch will detect and disable the unidirectional link, preventing a one-way forwarding condition.
If TenGigE1/1 interfaces are not installed or used, this is Not Applicable.
Verify the Aviat WTM has LACP enabled and configured on TenGigE1/1 for the uplink switch connection to provide unidirectional link failure detection.
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> L2 Link Aggregation. 3. Verify the "Enabled" checkbox under "LACP Global" is selected. 4. Verify an LACP bundle exists under "LACP Bundles" with the following settings: - "Load Balance Hash" is set to an appropriate hashing algorithm. - TenGigE1/1 is listed as a member interface with "Mode" set to "Active" and "Timeout" set to "Short".
If LACP is not globally enabled, or if TenGigE1/1 is not configured as a member of a LACP bundle with mode set to active and timeout set to short, this is a finding.
Configure the Aviat WTM to enable LACP and assign TenGigE1/1 to a bundle for the uplink switch connection.
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Switching and Routing >> L2 Link Aggregation. 3. Select the "Enabled" checkbox under "LACP Global". 4. Under "LACP Bundles", click "ADD" to create a new bundle. 5. Set "Min Active Links" to "1". 6. Set "Load Balance Hash" to the appropriate hashing algorithm in accordance with site requirements. 7. For the TenGigE1/1 interface row, set "Mode" to "Active" and "Timeout" to "Short". 8. Click "Commit". 9. On the uplink switch, configure the port connecting to TenGigE1/1 with LACP in active mode and short timeout in accordance with the uplink switch vendor documentation.