STIGQter STIGQter: STIG Summary: Cisco ACI Layer 2 Switch Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI layer 2 switch must employ a first-hop-security (FHS) policy to protect against denial-of-service (DoS) attacks.

DISA Rule

SV-272045r1168271_rule

Vulnerability Number

V-272045

Group Title

SRG-NET-000705-L2S-000110

Rule Version

CACI-L2-000017

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the FHS policy.

Tenants >> {{Your_Tenant}} >> Networking >> Bridge domains >> {{your_BridgeDomain_Name}} >> Policy >> Advanced/Troubleshooting

Create a First Hop Security Policy.

Check Contents

Verify the FHS policy is configured.

To validate the BD has FHS configured, navigate to Tenants >> {{Your_Tenant}} >> Networking >> Bridge domains >> {{your_BridgeDomain_Name}} >> Policy >> Advanced/Troubleshooting. Search for First Hop Security Policy.

To validate the First hop Security Policy settings, navigate to Tenants >> Policies >> Protocol >> First Hop Security.

If an FHS policy is not configured with all required settings, this is a finding.

Vulnerability Number

V-272045

Documentable

False

Rule Version

CACI-L2-000017

Severity Override Guidance

Verify the FHS policy is configured.

To validate the BD has FHS configured, navigate to Tenants >> {{Your_Tenant}} >> Networking >> Bridge domains >> {{your_BridgeDomain_Name}} >> Policy >> Advanced/Troubleshooting. Search for First Hop Security Policy.

To validate the First hop Security Policy settings, navigate to Tenants >> Policies >> Protocol >> First Hop Security.

If an FHS policy is not configured with all required settings, this is a finding.

Check Content Reference

M

Target Key

5683