Free DISA STIG and SRG Library | Vaulted

V-101605

The Cisco switch must be configured to have gratuitous ARP disabled on all external interfaces.

Finding ID
CISC-RT-000150
Rule ID
SV-110709r1_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-NET-000362-RTR-000111
CCI
CCI-002385
Target Key
(None)
Documentable
No
Discussion

A gratuitous ARP is an ARP broadcast in which the source and destination MAC addresses are the same. It is used to inform the network about a host IP address. A spoofed gratuitous ARP message can cause network mapping information to be stored incorrectly, causing network malfunction.

Fix Text

Disable gratuitous ARP as shown in the example below: SW1(config)#no ip gratuitous-arps

Check Content

Review the configuration to determine if gratuitous ARP is disabled. The following command should not be found in the switch configuration: ip gratuitous-arps Note: With Cisco IOS, gratuitous ARP is enabled and disabled globally. If gratuitous ARP is enabled on any external interface, this is a finding.