STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to implement message authentication and secure communications for all control plane protocols.

DISA Rule

SV-272082r1168145_rule

Vulnerability Number

V-272082

Group Title

SRG-NET-000230-RTR-000001

Rule Version

CACI-RT-000022

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure secure communications and message authentication on all control plane protocols.

1. Verify Secure Communication:
- Navigate to Fabric >> Fabric Policies >> Policies >> Pod >> Management Access.
- Verify SSH and SSL protocols are enabled for APIC management. Configure the ports used for SSH and SSL connections as needed.

2. Configure Message Authentication:
- Navigate to Fabric >> Fabric Policies >> Pod Policies >> Policies >> Interconnect.
- Enable IPsec for FI communication to ensure secure communication between the APIC and the switches.
- Configure the IPsec parameters, such as the encryption algorithm and authentication method.

3. Configure OpFlex for Southbound Communication to use TLS:
Note: OpFlex is a southbound protocol designed to facilitate communications between the SDN Controller and the switches and routers.

4. Enable Trust Domain:
- Navigate to Fabric >> Fabric Policies >> Pod Policies >> Policies >> Trust Domain.
- Enable the Trust Domain to ensure that only trusted devices can communicate with the APIC.
- Configure the Trust Domain parameters, such as the certificate authority and the trusted devices.

To configure BGP neighbor authentication keys on Cisco ACI border leaf switches using a different authentication key for each AS peer, configure the BGP Peer Connectivity Profile within the L3Out configuration.

1. In the APIC GUI, go to Tenants >> All Tenants >> your_tenant >> Networking >> L3Outs >> your_l3out.
2. Expand Logical Node Profiles >> node_profile.
3. Select Logical Interface Profiles >> interface_profile (where the BGP peering is configured).
4. Within the Logical Interface Profile, locate or create the BGP Peer Connectivity Profile associated with the peer you want to authenticate. Edit or create a profile.
5. In the BGP Peer Connectivity Profile settings:
- Remote Autonomous System Number: Specify the AS number of the peer.
- Password: Enter the authentication key/password for this specific peer.
- Confirm Password: Re-enter the same password.
- Other settings, such as peer controls, address type controls, and route control profiles, can be adjusted as needed for the BGP peering configuration.

6. Repeat the steps for each peer that must be configured. Create separate BGP Peer Connectivity profiles for each individual BGP peer, with different passwords for each. Ensure the peer devices have the matching authentication key/password configured for successful BGP peering.

Check Contents

Verify secure communications and message authentication on all control plane protocols is configured.

1. Verify Secure Communication:
- Navigate to Fabric >> Fabric Policies >> Policies >> Pod >> Management Access.
- Verify SSH and SSL protocols are enabled for APIC management.

2. Verify Message Authentication:
- Navigate to Fabric >> Fabric Policies >> Pod Policies >> Policies >> Interconnect.
- Verify IPsec for FI communication is enabled.

3. Verify OpFlex for Southbound Communication is set to TLS.

4. Navigate to Fabric >> Fabric Policies >> Pod Policies >> Policies >> Trust Domain.
- Verify the Trust Domain is enabled and configured.

Verify BGP neighbor authentication keys on Cisco ACI border leaf switches are configured to use a different authentication key for each AS peer.

1. Navigate to Tenants >> All Tenants >> your_tenant >> Networking >> L3Outs >> your_l3out.
2. Expand Logical Node Profiles >> node_profile.
3. Select Logical Interface Profiles >> interface_profile (where the BGP peering is configured).
4. Within the Logical Interface Profile, review each BGP Peer Connectivity profiles for each individual BGP peer.
5. In the BGP Peer Connectivity Profile settings, review the Password to verify each peer has a unique password.

If message authentication and secure communications is not configured for all control plane protocols, this is a finding.

Vulnerability Number

V-272082

Documentable

False

Rule Version

CACI-RT-000022

Severity Override Guidance

Verify secure communications and message authentication on all control plane protocols is configured.

1. Verify Secure Communication:
- Navigate to Fabric >> Fabric Policies >> Policies >> Pod >> Management Access.
- Verify SSH and SSL protocols are enabled for APIC management.

2. Verify Message Authentication:
- Navigate to Fabric >> Fabric Policies >> Pod Policies >> Policies >> Interconnect.
- Verify IPsec for FI communication is enabled.

3. Verify OpFlex for Southbound Communication is set to TLS.

4. Navigate to Fabric >> Fabric Policies >> Pod Policies >> Policies >> Trust Domain.
- Verify the Trust Domain is enabled and configured.

Verify BGP neighbor authentication keys on Cisco ACI border leaf switches are configured to use a different authentication key for each AS peer.

1. Navigate to Tenants >> All Tenants >> your_tenant >> Networking >> L3Outs >> your_l3out.
2. Expand Logical Node Profiles >> node_profile.
3. Select Logical Interface Profiles >> interface_profile (where the BGP peering is configured).
4. Within the Logical Interface Profile, review each BGP Peer Connectivity profiles for each individual BGP peer.
5. In the BGP Peer Connectivity Profile settings, review the Password to verify each peer has a unique password.

If message authentication and secure communications is not configured for all control plane protocols, this is a finding.

Check Content Reference

M

Target Key

5684