STIGQter STIGQter: STIG Summary: Cisco ACI Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI layer 2 switch must have Unknown Unicast Flood Blocking (UUFB) set to "Hardware Proxy".

DISA Rule

SV-272033r1168251_rule

Vulnerability Number

V-272033

Group Title

SRG-NET-000362-L2S-000024

Rule Version

CACI-L2-000005

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure each Bridge Domain to handle unknown unicast flood blocking.

1. Navigate to Tenant >> Networking >> Bridge Domains >> Policy >> General.
2. Expand Networking and right-click "Create Bridge Domain" to open the dialog box and fill out the form.
- In the L2 Unknown Unicast box, select "Hardware Proxy".
3. Click "NEXT".
4. Complete the Bridge Domain configuration and click "Finish".

Check Contents

Verify each Bridge Domain used is configured to block unknown unicast traffic.

1. Navigate to Tenant >> Networking >> Bridge Domains >> Policy >> General and inspect each Tenant's Bridge Domain configuration.
2. Expand Networking and right-click each Bridge Domain.
- Verify the L2 Unknown Unicast box is set to "Hardware Proxy".

If any user-facing or untrusted access switch ports do not have UUFB set to "Hardware Proxy", this is a finding.

Vulnerability Number

V-272033

Documentable

False

Rule Version

CACI-L2-000005

Severity Override Guidance

Verify each Bridge Domain used is configured to block unknown unicast traffic.

1. Navigate to Tenant >> Networking >> Bridge Domains >> Policy >> General and inspect each Tenant's Bridge Domain configuration.
2. Expand Networking and right-click each Bridge Domain.
- Verify the L2 Unknown Unicast box is set to "Hardware Proxy".

If any user-facing or untrusted access switch ports do not have UUFB set to "Hardware Proxy", this is a finding.

Check Content Reference

M

Target Key

5683