| Checked | Name | Title |
|---|
| ☐ | SV-272061r1168386_rule | The Cisco ACI must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies. |
| ☐ | SV-272062r1168387_rule | The BGP Cisco ACI must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS). |
| ☐ | SV-272063r1168094_rule | The BGP Cisco ACI must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS). |
| ☐ | SV-272064r1168097_rule | The BGP Cisco ACI must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute. |
| ☐ | SV-272069r1168390_rule | The multicast Cisco ACI must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled. |
| ☐ | SV-272073r1168393_rule | The Cisco ACI multicast rendezvous point (RP) must be configured to filter Protocol Independent Multicast (PIM) Register messages received from the designated router (DR) for any undesirable multicast groups and sources. |
| ☐ | SV-272074r1168396_rule | The multicast rendezvous point (RP) Cisco ACI must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the designated router (DR) for any undesirable multicast groups. |
| ☐ | SV-272075r1114309_rule | The Cisco ACI must be configured to log all packets that have been dropped. |
| ☐ | SV-272076r1168127_rule | The Cisco ACI must not be configured to have any feature enabled that calls home to the vendor. |
| ☐ | SV-272077r1168399_rule | The Cisco ACI must be configured to use encryption for routing protocol authentication. |
| ☐ | SV-272078r1168402_rule | The Cisco ACI must be configured to authenticate all routing protocol messages using a NIST-validated FIPS 198-1 message authentication code algorithm. |
| ☐ | SV-272079r1168423_rule | The Cisco ACI must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself. |
| ☐ | SV-272081r1168142_rule | The Cisco ACI must be configured to only permit management traffic that ingresses and egresses the OOBM interface. |
| ☐ | SV-272082r1168145_rule | The Cisco ACI must be configured to implement message authentication and secure communications for all control plane protocols. |
| ☐ | SV-272086r1114094_rule | The Cisco ACI must be configured to have gratuitous ARP (GARP) disabled on all external interfaces. |
| ☐ | SV-272087r1168151_rule | The Cisco ACI must be configured to have Internet Control Message Protocol (ICMP) mask replies disabled on all external interfaces. |
| ☐ | SV-272088r1168406_rule | The BGP Cisco ACI must be configured to use the maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks. |
| ☐ | SV-272089r1168408_rule | The BGP Cisco ACI must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer. |
| ☐ | SV-272091r1168160_rule | The multicast rendezvous point (RP) must be configured to rate limit the number of Protocol Independent Multicast (PIM) Register messages. |
| ☐ | SV-272092r1168163_rule | The Cisco ACI must be configured to limit the mroute states created by Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) reports on a Cisco APIC Bridge Domain (BD) or interface. |
| ☐ | SV-272094r1168411_rule | Cisco ACI must be configured so the BGP neighbor is directly connected and will not connect a BGP session to a directly connected neighbor device's loopback address. |
| ☐ | SV-272095r1168413_rule | The Cisco ACI multicast must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups and only from sources that have been approved by the organization. |
| ☐ | SV-272098r1168415_rule | The Cisco ACI must be configured to use its loopback address as the source address for internal Border Gateway Protocol (iBGP) peering sessions. |
| ☐ | SV-272101r1168417_rule | The Cisco ACI must not be configured to use IPv6 site local unicast addresses. |
| ☐ | SV-272103r1168419_rule | The Cisco ACI must establish organization-defined alternate communication paths for system operations organizational command and control. |
| ☐ | SV-272104r1168421_rule | The Cisco ACI must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection. |