STIGQter STIGQter: STIG Summary: Cisco ACI NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

DISA Rule

SV-271920r1168358_rule

Vulnerability Number

V-271920

Group Title

SRG-APP-000142-NDM-000245

Rule Version

CACI-ND-000005

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the APIC GUI:
Navigate to Fabric >> Fabric Policies >> Policies >> Pod >> Management Access. This will limit the ports the management plane is listening on.

Add an OOB contract to limit the mgmt interfaces to only accept the required port traffic.
Navigate to Tenants >> mgmt >> Node Management EPGs >> Out-Of-Band EPG - Default.

Disable insecure or unnecessary ports/protocols, services, and ciphers that have been enabled, such as HTTP, FTP, unauthorized TLS versions, and TELNET.

Check Contents

From the APIC GUI:
1. Navigate to Fabric >> Fabric Policies >> Policies >> Pod >> Management Access.
2. Navigate to Tenants >> mgmt >> Node Management EPGs >> Out-Of-Band EPG - Default.

Verify insecure or unnecessary ports/protocols, services, and ciphers are disabled. This is the default.

If the Cisco ACI is configured to listen or run unnecessary and/or nonsecure functions, ports, protocols, and/or services, this is a finding.

Vulnerability Number

V-271920

Documentable

False

Rule Version

CACI-ND-000005

Severity Override Guidance

From the APIC GUI:
1. Navigate to Fabric >> Fabric Policies >> Policies >> Pod >> Management Access.
2. Navigate to Tenants >> mgmt >> Node Management EPGs >> Out-Of-Band EPG - Default.

Verify insecure or unnecessary ports/protocols, services, and ciphers are disabled. This is the default.

If the Cisco ACI is configured to listen or run unnecessary and/or nonsecure functions, ports, protocols, and/or services, this is a finding.

Check Content Reference

M

Target Key

5682