STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to limit the mroute states created by Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) reports on a Cisco APIC Bridge Domain (BD) or interface.

DISA Rule

SV-272092r1168163_rule

Vulnerability Number

V-272092

Group Title

SRG-NET-000362-RTR-000122

Rule Version

CACI-RT-000032

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure a global or interface basis to limit the number of mroute states resulting from IGMP or MLD membership reports.

Tenants >> {{your_Tenant}} >> Networking >> Bridge Domain >> {{your_Bridge_Domain}} >> Policy >> General >> IGMP Policy >> set the Maximum Multicast Entries


Note: This setting is used to limit the mroute states for the BD or interface created by IGMP reports. Default is disabled, no limit enforced. Valid range is 1-4294967295.

Check Contents

Review the relevant BD configuration. Verify it is configured to limit the number of multicast routes (mroute states) generated by IGMP or MLD reports.

Tenants >> {{your_Tenant}} >> Networking >> Bridge Domain >> {{your_Bridge_Domain}} >> Policy >> General >> IGMP Policy >> set the Maximum Multicast Entries

If the ACI is not limiting multicast requests via IGMP or MLD on a global or interfaces basis, this is a finding.

Vulnerability Number

V-272092

Documentable

False

Rule Version

CACI-RT-000032

Severity Override Guidance

Review the relevant BD configuration. Verify it is configured to limit the number of multicast routes (mroute states) generated by IGMP or MLD reports.

Tenants >> {{your_Tenant}} >> Networking >> Bridge Domain >> {{your_Bridge_Domain}} >> Policy >> General >> IGMP Policy >> set the Maximum Multicast Entries

If the ACI is not limiting multicast requests via IGMP or MLD on a global or interfaces basis, this is a finding.

Check Content Reference

M

Target Key

5684