STIGQter STIGQter: STIG Summary: Cisco ACI Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI layer 2 switch must authenticate all network-connected endpoint devices before establishing any connection.

DISA Rule

SV-272032r1168262_rule

Vulnerability Number

V-272032

Group Title

SRG-NET-000343-L2S-000016

Rule Version

CACI-L2-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create Authentication Policy and associate with a policy group.

1. On the menu bar, click Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Policy Groups >> (Leaf Access port, PC interface or VPC interface) >> {{your_policy_name}} >> Advance Policies.
2. Path to Validate the policy group is assigned to an interface: Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Profiles >> {{your_profile}}.

Check Contents

Verify the switch authenticates all network-connected endpoint devices before establishing any connection.

1. On the menu bar, click Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Policy Groups >> (Leaf Access port, PC interface or VPC interface) >> {{your_policy_name}} >> Advance Policies.
2. Path to Validate the policy group is assigned to an interface: Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Profiles >> {{your_profile}}.

If The Cisco ACI layer 2 switch does not authenticate all network-connected endpoint devices before establishing any connection, this is a finding.

Vulnerability Number

V-272032

Documentable

False

Rule Version

CACI-L2-000004

Severity Override Guidance

Verify the switch authenticates all network-connected endpoint devices before establishing any connection.

1. On the menu bar, click Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Policy Groups >> (Leaf Access port, PC interface or VPC interface) >> {{your_policy_name}} >> Advance Policies.
2. Path to Validate the policy group is assigned to an interface: Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Profiles >> {{your_profile}}.

If The Cisco ACI layer 2 switch does not authenticate all network-connected endpoint devices before establishing any connection, this is a finding.

Check Content Reference

M

Target Key

5683