STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must establish organization-defined alternate communication paths for system operations organizational command and control.

DISA Rule

SV-272103r1168419_rule

Vulnerability Number

V-272103

Group Title

SRG-NET-000760-RTR-000160

Rule Version

CACI-RT-000043

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure logical separation using EPGs, bridge domains, and/or tenants in accordance with the SSP. There are a large number of spots to validate that each EPG is using an organizational defined VLAN. That would be dependent on the VLAN pool associated with the Physical/ VMM Domains that the EPG is using.

1. Edit or create a physical domain in the GUI using the following path:
Tenants >> {{your_Tenant}} >> Application Profiles >> {{your_application_profile}} >> Application EPGs >> {{your_EPG}} > Domains

2. Create a VLAN pool on physical domains in the GUI:
Fabric >> Access Policies >> Physical and External Domains >> Physical Domains >> {{your_domain}}

3. For VMM Domain vlan pools, create a policy at the following GUI location:
Virtual Networking >> VMware >> {{your_VMM_Domain}} >> Policy >> General

Check Contents

Review the SSP and the ACI configuration to verify logical separation using EPGs, bridge domains, and/or tenants is configured.

There are a large number of places to validate that each EPG is using an organizational defined VLAN. That would be dependent on the VLAN pool associated with the Physical/ VMM Domains that the EPG is using.

To check the Physical domain in the GUI, use the following path:
Tenants >> {{your_Tenant}} >> Application Profiles >> {{your_application_profile}} >> Application EPGs >> {{your_EPG}} > Domains

After checking the domain, check the VLAN pool on the physical domains in the GUI:
Fabric >> Access Policies >> Physical and External Domains >> Physical Domains >> {{your_domain}}

For VMM Domain vlan pools, check the following GUI location:
Virtual Networking >> VMware >> {{your_VMM_Domain}} >> Policy >> General

If organization-defined alternate communication paths for system operations organizational command and control have not been established, this is a finding.

Vulnerability Number

V-272103

Documentable

False

Rule Version

CACI-RT-000043

Severity Override Guidance

Review the SSP and the ACI configuration to verify logical separation using EPGs, bridge domains, and/or tenants is configured.

There are a large number of places to validate that each EPG is using an organizational defined VLAN. That would be dependent on the VLAN pool associated with the Physical/ VMM Domains that the EPG is using.

To check the Physical domain in the GUI, use the following path:
Tenants >> {{your_Tenant}} >> Application Profiles >> {{your_application_profile}} >> Application EPGs >> {{your_EPG}} > Domains

After checking the domain, check the VLAN pool on the physical domains in the GUI:
Fabric >> Access Policies >> Physical and External Domains >> Physical Domains >> {{your_domain}}

For VMM Domain vlan pools, check the following GUI location:
Virtual Networking >> VMware >> {{your_VMM_Domain}} >> Policy >> General

If organization-defined alternate communication paths for system operations organizational command and control have not been established, this is a finding.

Check Content Reference

M

Target Key

5684