STIGQter STIGQter: STIG Summary:

Cisco ACI Layer 2 Switch Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-272029r1168259_ruleThe Cisco ACI layer 2 switch must uniquely identify all network-connected endpoint devices before establishing any connection.
SV-272032r1168262_ruleThe Cisco ACI layer 2 switch must authenticate all network-connected endpoint devices before establishing any connection.
SV-272033r1168251_ruleThe Cisco ACI layer 2 switch must have Unknown Unicast Flood Blocking (UUFB) set to "Hardware Proxy".
SV-272037r1168273_ruleThe Cisco ACI layer 2 switch must enable port security.
SV-272038r1168256_ruleThe Cisco ACI layer 2 switch must have Storm Control configured on all host-facing switch ports.
SV-272039r1168265_ruleThe Cisco ACI layer 2 switch must have Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) snooping configured on all VLANs.
SV-272045r1168271_ruleThe Cisco ACI layer 2 switch must employ a first-hop-security (FHS) policy to protect against denial-of-service (DoS) attacks.