STIGQter STIGQter: STIG Summary:

Cisco ACI Router Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-272061r1168386_ruleThe Cisco ACI must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.
SV-272062r1168387_ruleThe BGP Cisco ACI must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).
SV-272063r1168094_ruleThe BGP Cisco ACI must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS).
SV-272064r1168097_ruleThe BGP Cisco ACI must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.
SV-272069r1168390_ruleThe multicast Cisco ACI must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
SV-272073r1168393_ruleThe Cisco ACI multicast rendezvous point (RP) must be configured to filter Protocol Independent Multicast (PIM) Register messages received from the designated router (DR) for any undesirable multicast groups and sources.
SV-272074r1168396_ruleThe multicast rendezvous point (RP) Cisco ACI must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the designated router (DR) for any undesirable multicast groups.
SV-272075r1114309_ruleThe Cisco ACI must be configured to log all packets that have been dropped.
SV-272076r1168127_ruleThe Cisco ACI must not be configured to have any feature enabled that calls home to the vendor.
SV-272077r1168399_ruleThe Cisco ACI must be configured to use encryption for routing protocol authentication.
SV-272078r1168402_ruleThe Cisco ACI must be configured to authenticate all routing protocol messages using a NIST-validated FIPS 198-1 message authentication code algorithm.
SV-272079r1168423_ruleThe Cisco ACI must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself.
SV-272081r1168142_ruleThe Cisco ACI must be configured to only permit management traffic that ingresses and egresses the OOBM interface.
SV-272082r1168145_ruleThe Cisco ACI must be configured to implement message authentication and secure communications for all control plane protocols.
SV-272086r1114094_ruleThe Cisco ACI must be configured to have gratuitous ARP (GARP) disabled on all external interfaces.
SV-272087r1168151_ruleThe Cisco ACI must be configured to have Internet Control Message Protocol (ICMP) mask replies disabled on all external interfaces.
SV-272088r1168406_ruleThe BGP Cisco ACI must be configured to use the maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.
SV-272089r1168408_ruleThe BGP Cisco ACI must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer.
SV-272091r1168160_ruleThe multicast rendezvous point (RP) must be configured to rate limit the number of Protocol Independent Multicast (PIM) Register messages.
SV-272092r1168163_ruleThe Cisco ACI must be configured to limit the mroute states created by Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) reports on a Cisco APIC Bridge Domain (BD) or interface.
SV-272094r1168411_ruleCisco ACI must be configured so the BGP neighbor is directly connected and will not connect a BGP session to a directly connected neighbor device's loopback address.
SV-272095r1168413_ruleThe Cisco ACI multicast must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups and only from sources that have been approved by the organization.
SV-272098r1168415_ruleThe Cisco ACI must be configured to use its loopback address as the source address for internal Border Gateway Protocol (iBGP) peering sessions.
SV-272101r1168417_ruleThe Cisco ACI must not be configured to use IPv6 site local unicast addresses.
SV-272103r1168419_ruleThe Cisco ACI must establish organization-defined alternate communication paths for system operations organizational command and control.
SV-272104r1168421_ruleThe Cisco ACI must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.