STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to HP FlexFabric Switch L2S Security Technical Implementation Guide

V-66079

CAT II (Medium)

The HP FlexFabric Switch must enable Device Link Detection Protocol (DLDP) to protect against one-way connections.

Rule ID

SV-80569r1_rule

STIG

HP FlexFabric Switch L2S Security Technical Implementation Guide

Version

V1R3

CCIs

CCI-000366

Discussion

In topologies where fiber optic interconnections are used, physical misconnections can occur that allow a link to appear to be up when there is a mismatched set of transmit/receive pairs. When such a physical misconfiguration occurs, protocols such as STP can cause network instability. Device Link Detection Protocol (DLDP) is a layer 2 protocol that can detect these physical misconfigurations by verifying that traffic is flowing bidirectionally between neighbors. Ports with DLDP enabled periodically transmit packets to neighbor devices. If the packets are not echoed back within a specific time frame, the link is flagged as unidirectional and the interface is shut down.

Check Content

If any of the switch ports have fiber optic interconnections with neighbors, review the HP FlexFabric Switch configuration to verify that DLDP is enabled globally or on a per interface basis.

If the HP FlexFabric Switch has fiber optic interconnections with neighbors and DLDP is not enabled, this is a finding.

<HP> display dldp
DLDP global status : disable
DLDP interval : 5s
DLDP work-mode : enhance
DLDP authentication-mode : none
DLDP unidirectional-shutdown : auto
DLDP delaydown-timer : 1s
The number of enabled ports is 2.
[HP-Interface Ethernet1/1]
DLDP port state : advertisement
DLDP link state : up
The neighbor number of the port is 0.
[HP-Interface Ethernet1/2]
DLDP port state : advertisement
DLDP link state : up
The neighbor number of the port is 0.

Fix Text

Configure the HP FlexFabric Switch to enable Device Link Detection Protocol (DLDP) to protect against one-way connections.

[HP]dldp global enable

[HP-Ten-GigabitEthernet1/0/47]dldp enable