STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to have gratuitous ARP (GARP) disabled on all external interfaces.

DISA Rule

SV-272086r1114094_rule

Vulnerability Number

V-272086

Group Title

SRG-NET-000362-RTR-000111

Rule Version

CACI-RT-000026

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable GARP for each L3OUT Bridge Domain:
1. In the APIC GUI navigation pane, select "Tenant" and complete the following for each tenant listed.
2. Expand "Networking", right-click, "Create Bridge Domain" to open the dialog box, and fill out the form.
- In the Layer 3 Configurations tab, GARP based detection must not be enabled.
3. Click "NEXT".
4. Complete the Bridge Domain configuration.
5. Click "Finish".

Check Contents

Review the configuration for each L3OUT Bridge Domain to determine if gratuitous ARP is disabled:
1. In the APIC GUI Navigation pane, select "Tenant" and inspect each Tenant's Bridge Domain configuration.
2. Expand "Networking" and right-click each Bridge Domain.
3. View the Layer 3 configuration tab. Verify GARP-based detection is not enabled.

If GARP is enabled on any external interface, this is a finding.

Vulnerability Number

V-272086

Documentable

False

Rule Version

CACI-RT-000026

Severity Override Guidance

Review the configuration for each L3OUT Bridge Domain to determine if gratuitous ARP is disabled:
1. In the APIC GUI Navigation pane, select "Tenant" and inspect each Tenant's Bridge Domain configuration.
2. Expand "Networking" and right-click each Bridge Domain.
3. View the Layer 3 configuration tab. Verify GARP-based detection is not enabled.

If GARP is enabled on any external interface, this is a finding.

Check Content Reference

M

Target Key

5684