STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to use its loopback address as the source address for internal Border Gateway Protocol (iBGP) peering sessions.

DISA Rule

SV-272098r1168415_rule

Vulnerability Number

V-272098

Group Title

SRG-NET-000512-RTR-000001

Rule Version

CACI-RT-000038

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure BGP for the relevant L3Out to use the switch's loopback address as the source address for all iBGP peering. This configures the switch to use the loopback interface as the source IP for all BGP updates sent to the specified peer.

- Navigate to Tenants >> {{your_Tenant}} >> Networking >> L3Out >> {{your_l3out}} >> Logical Node Profiles >> {{your_Logical_node_Profile}} >> Policy >> Node.
- Double click the Node(Leaf) and look for the option to select "use Router ID as loopback" or set the loopback address to which to build the BGP connection and unselect "use router ID as Loopback".

After setting the loopback address, navigate to Tenants >> {{your_Tenant}} >> L3Out >> {{your_l3out}} >> Logical Node Profiles >> {{your_Logical_node_Profile}} >> Policy >> BGP Peer Connectivity. Add the loopback.

Check Contents

Review the switch configuration to verify a loopback address has been configured.

Tenants >> {{your_Tenant}} >> L3Out >> {{your_l3out}} >> Logical Node Profiles >> {{your_Logical_node_Profile}} >> Policy >> BGP Peer Connectivity add your loopback

If the switch does not use its loopback address as the source address for all iBGP sessions, this is a finding.

Vulnerability Number

V-272098

Documentable

False

Rule Version

CACI-RT-000038

Severity Override Guidance

Review the switch configuration to verify a loopback address has been configured.

Tenants >> {{your_Tenant}} >> L3Out >> {{your_l3out}} >> Logical Node Profiles >> {{your_Logical_node_Profile}} >> Policy >> BGP Peer Connectivity add your loopback

If the switch does not use its loopback address as the source address for all iBGP sessions, this is a finding.

Check Content Reference

M

Target Key

5684