STIGUI
V-214646CAT II — Medium severitySV-214646r856524_rule

The HP FlexFabric Switch must have STP Loop Protection enabled all non-designated STP switch ports.

Rule version HFFS-L2-000012 · STIG v1 · 2026-09-10

Discussion

The Spanning Tree Protocol (STP) loop Protection feature provides additional protection against STP loops. An STP loop is created when an STP blocking port in a redundant topology erroneously transitions to the forwarding state. In its operation, STP relies on continuous reception and transmission of BPDUs based on the port role. The designated port transmits BPDUs, and the non-designated port receives BPDUs. When one of the ports in a physically redundant topology no longer receives BPDUs, the STP conceives that the topology is loop free. Eventually, the blocking port from the alternate or backup port becomes a designated port and moves to a forwarding state. This situation creates a loop. The loop Protection feature makes additional checks. If BPDUs are not received on a non-designated port and loop guard is enabled, that port is moved into the STP loop-inconsistent blocking state.

Check

Review the HP FlexFabric Switch configuration to verify that STP Loop Protection is enabled.

If STP Loop Protection is not configured globally or at a minimum on non-designated STP ports, this is a finding.

[HPinterface Ten-GigabitEthernet1/0/8] port link-mode bridge stp loop-protection

Fix

Configure the HP FlexFabric Switch to have STP Loop Protection enabled globally or at a minimum on all non-designated switch ports.

[HPinterface Ten-GigabitEthernet1/0/8] stp loop-protection

Identifiers

Group ID
V-214646
Group title
SRG-NET-000362-L2S-000023
Rule ID
SV-214646r856524_rule
Check ID
C-15849r368691_chk
Fix ID
F-15847r368692_fix