STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to log all packets that have been dropped.

DISA Rule

SV-272075r1114309_rule

Vulnerability Number

V-272075

Group Title

SRG-NET-000078-RTR-000001

Rule Version

CACI-RT-000015

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure ACLs to log packets that are dropped. Use the APIC GUI to navigate to each tenant:
1. Go to the contract section and either create a new contract or modify an existing one where drop logging is to be implemented.
2. Within the contract, create the necessary filter rules based on the desired criteria (e.g., source/destination IP, port, protocol) and set the "Action" to "Deny" with the "Directive" set to "Log".
3. Assign the contract to the relevant endpoint groups (EPGs) to enforce the policy on traffic between them.

Check Contents

Use the APIC GUI to navigate to each tenant. Within each contract, review each rule with "Action" set to "Deny". Verify these rules have the "Directive" set to "Log".

If packets being dropped at interfaces are not logged, this is a finding.

Vulnerability Number

V-272075

Documentable

False

Rule Version

CACI-RT-000015

Severity Override Guidance

Use the APIC GUI to navigate to each tenant. Within each contract, review each rule with "Action" set to "Deny". Verify these rules have the "Directive" set to "Log".

If packets being dropped at interfaces are not logged, this is a finding.

Check Content Reference

M

Target Key

5684