STIGQter STIGQter: STIG Summary: Cisco ACI NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).

DISA Rule

SV-271917r1114333_rule

Vulnerability Number

V-271917

Group Title

SRG-APP-000395-NDM-000310

Rule Version

CACI-ND-000002

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the CLI configuration mode, enable FIPS mode on all nodes and then reboot all nodes to activate FIPS compliance.

apic1(config)# fips mode enable

Check Contents

To show the current FIPS mode setting, use the show command from the CLI configuration mode.

apic1(config) show fips status

If FIPS mode is not set to "Enable", this is a finding.

Vulnerability Number

V-271917

Documentable

False

Rule Version

CACI-ND-000002

Severity Override Guidance

To show the current FIPS mode setting, use the show command from the CLI configuration mode.

apic1(config) show fips status

If FIPS mode is not set to "Enable", this is a finding.

Check Content Reference

M

Target Key

5682