The layer 2 switch must have all trunk links enabled statically.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-206665 | SRG-NET-000512 | SRG-NET-000512-L2S-000005 | SV-206665r1188390_rule | 2026-02-12 | 3 |
Description
When trunk negotiation is enabled dynamically via features such as Dynamic Trunk Protocol (DTP) or similar, considerable time can be spent negotiating trunk settings (802.1q or ISL) when a node or interface is restored. While this negotiation is happening, traffic is dropped because the link is up from a layer 2 perspective. Packet loss can be eliminated by setting the interface statically to trunk mode, thereby avoiding dynamic trunk protocol negotiation and significantly reducing any outage when restoring a failed link or switch.
ℹ️ Check
Review the switch configuration to verify that trunk negotiation is disabled by statically configuring all trunk links. Configuring a command to manually disable negotiation may also be required for some switch platforms.
If trunk negotiation is enabled on any interface, this is a finding.
✔️ Fix
Configure the switch to enable trunk links statically.