STIGQter STIGQter: STIG Summary: Cisco ACI Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.

DISA Rule

SV-272104r1168421_rule

Vulnerability Number

V-272104

Group Title

SRG-NET-000362-RTR-000110

Rule Version

CACI-RT-000044

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Protect against known types of DoS attacks on the route processor by implementing a CoPP policy. To meet this requirement, configure the COPP policy on each device, QOS to ensure the correct traffic is being dropped, and verify all l3 outs have the correct contracts applied to them.

These policies must be applied to the Leaf and or interface policies accordingly.

CoPP Policy:
Fabric >> Access Policies >> Policies >> Switch >> CoPP Pre-Filter for Leaf / CoPP Leaf

Fabric >> Access Policies >> Policies >> Interface >> CoPP Interface

QOS: Since there are so many locations and settings required for this aspect, reference the QOS documentation to access these settings: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/kb/Cisco-APIC-and-QoS.html

Configure L3Out contracts include the CoPP policy. Inspect the policy at the following location:

Tenants >> {{your_Tenant}} >> Networking >> L3Outs >> {{your_l3out}} >> External EPGs >> {{your_External_EPG}} >> Policy >> Contract

Check Contents

Verify a Control Plane Policing (CoPP) policy is applied to the Leaf and or interface policies accordingly:

Fabric >> Access Policies >> Policies >> Switch >> CoPP Pre-Filter for Leaf / CoPP Leaf

Fabric >> Access Policies >> Policies >> Interface >> CoPP Interface

Verify L3Out contracts include the CoPP policy. Inspect the policy at the following location:

Tenants >> {{your_Tenant}} >> Networking >> L3Outs >> {{your_l3out}} >> External EPGs >> {{your_External_EPG}} >> Policy >> Contract

If the CoPP policy is not configured on all Leaf and/or interfaces, this is a finding.

Vulnerability Number

V-272104

Documentable

False

Rule Version

CACI-RT-000044

Severity Override Guidance

Verify a Control Plane Policing (CoPP) policy is applied to the Leaf and or interface policies accordingly:

Fabric >> Access Policies >> Policies >> Switch >> CoPP Pre-Filter for Leaf / CoPP Leaf

Fabric >> Access Policies >> Policies >> Interface >> CoPP Interface

Verify L3Out contracts include the CoPP policy. Inspect the policy at the following location:

Tenants >> {{your_Tenant}} >> Networking >> L3Outs >> {{your_l3out}} >> External EPGs >> {{your_External_EPG}} >> Policy >> Contract

If the CoPP policy is not configured on all Leaf and/or interfaces, this is a finding.

Check Content Reference

M

Target Key

5684