02-11-2021 12:21 AM
I posted a previous discussion in another community regarding a few requirements to make my Cisco C921-4P router/switch. Someone explained to me that some commands may not work with this platform. specifically the ones below.
Both of these requirements have commands that can be entered. However I am assuming since this is a router switch combo either they have some work around or they cannot be configured on this platform. If anyone has any input and can help with these it would be greatly appreciated.
Solved! Go to Solution.
02-11-2021 07:16 AM
I think the 900 series routers are part of ISR family that run IOS-XE. So, for STIG requirements, there should be a command to disable Gratuitous ARP (no IP arp gratuitous) if it is not available or issuing this command can cause operational issues, then that is what needs to be stated in the compliance document as the workaround. Regarding the second command, the ISRs mainly have routed ports so, not sure if you can add switch port-security parameters to the interfaces.
HTH
02-11-2021 07:16 AM
I think the 900 series routers are part of ISR family that run IOS-XE. So, for STIG requirements, there should be a command to disable Gratuitous ARP (no IP arp gratuitous) if it is not available or issuing this command can cause operational issues, then that is what needs to be stated in the compliance document as the workaround. Regarding the second command, the ISRs mainly have routed ports so, not sure if you can add switch port-security parameters to the interfaces.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide