STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to only permit management traffic that ingresses and egresses the OOBM interface.

DISA Rule

SV-272081r1168142_rule

Vulnerability Number

V-272081

Group Title

SRG-NET-000205-RTR-000012

Rule Version

CACI-RT-000021

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to the relevant tenant to setup the OOB to limit what devices/ networks can access it. Utilize contracts in the following settings:

Tenant >> Tenant mgmt >> Node Management Addresses >> Static Node Management Addresses

Tenant >> Tenant mgmt >> Node Management EPGs >> Out-of-Band EPG default

Tenant >> Tenant mgmt >> External Management Network Instance Profiles >> {{YourInstanceProfile}}

Check Contents

To setup the OOB to limit what devices/ networks can access it, use the contracts in the following settings:

Tenant >> Tenant mgmt >> Node Management Addresses >> Static Node Management Addresses

Tenant >> Tenant mgmt >> Node Management EPGs >> Out-of-Band EPG default

Tenant >> Tenant mgmt >> External Management Network Instance Profiles >> {{YourInstanceProfile}}

If the Cisco ACI is not configured to only permit management traffic that ingresses and egresses the OOBM interface, this is a finding.

Vulnerability Number

V-272081

Documentable

False

Rule Version

CACI-RT-000021

Severity Override Guidance

To setup the OOB to limit what devices/ networks can access it, use the contracts in the following settings:

Tenant >> Tenant mgmt >> Node Management Addresses >> Static Node Management Addresses

Tenant >> Tenant mgmt >> Node Management EPGs >> Out-of-Band EPG default

Tenant >> Tenant mgmt >> External Management Network Instance Profiles >> {{YourInstanceProfile}}

If the Cisco ACI is not configured to only permit management traffic that ingresses and egresses the OOBM interface, this is a finding.

Check Content Reference

M

Target Key

5684