STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to use encryption for routing protocol authentication.

DISA Rule

SV-272077r1168399_rule

Vulnerability Number

V-272077

Group Title

SRG-NET-000168-RTR-000077

Rule Version

CACI-RT-000017

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure one or more PSKs used to generate encryption keys for the routing protocol authentication process. Navigate to Tenants >> {{your_tenants}} >> Networking >> L3Outs >> {{your_L3Out}} >> Logical Node Profiles >> {{your_node_profile}} >> Logical Interface Profiles >> {{your_interface_Profile} >> OSPF|EIGRP|BGP Interface profile.

Check Contents

Verify PSKs are configured. Navigate to Tenants >> {{your_tenants}} >> Networking >> L3Outs >> {{your_L3Out}} >> Logical Node Profiles >> {{your_node_profile}} >> Logical Interface Profiles >> {{your_interface_Profile} >> OSPF|EIGRP|BGP Interface profile.

If PSKs are not configured to use encryption for routing protocol authentication, this is a finding.

Vulnerability Number

V-272077

Documentable

False

Rule Version

CACI-RT-000017

Severity Override Guidance

Verify PSKs are configured. Navigate to Tenants >> {{your_tenants}} >> Networking >> L3Outs >> {{your_L3Out}} >> Logical Node Profiles >> {{your_node_profile}} >> Logical Interface Profiles >> {{your_interface_Profile} >> OSPF|EIGRP|BGP Interface profile.

If PSKs are not configured to use encryption for routing protocol authentication, this is a finding.

Check Content Reference

M

Target Key

5684