STIGUI
V-214653CAT II — Medium severitySV-214653r1188390_rule

The HP FlexFabric Switch must have all trunk links enabled statically.

Rule version HFFS-L2-000022 · STIG v1 · 2026-09-10

Discussion

When trunk negotiation is enabled via Dynamic Trunk Protocol (DTP), considerable time can be spent negotiating trunk settings (802.1q or ISL) when a node or interface is restored. While this negotiation is happening, traffic is dropped because the link is up from a layer 2 perspective. Packet loss can be eliminated by setting the interface statically to trunk mode, thereby avoiding dynamic trunk protocol negotiation and significantly reducing any outage when restoring a failed link or switch.

Check

Review the HP FlexFabric Switch configuration to verify that trunk negotiation is disabled by statically configuring all trunk links. Configuring a command to manually disable negotiation may also be required for some switch platforms.

If trunk negotiation is enabled on any interface, this is a finding.

Sample output: interface GigabitEthernet1/0/1 port link-type trunk port trunk permit vlan X

Fix

Configure the HP FlexFabric Switch to enable trunk links statically.

[HP-GigabitEthernet1/0/1]port link-type trunk

Identifiers

Group ID
V-214653
Group title
SRG-NET-000512-L2S-000005
Rule ID
SV-214653r1188390_rule
Check ID
C-15856r368712_chk
Fix ID
F-15854r368713_fix