The BGP Cisco ACI must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-272080 | SRG-NET-000205-RTR-000006 | CACI-RT-000020 | SV-272080r1113986_rule | 2025-06-18 | 1 |
| Description |
|---|
| Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a nonoptimized path. |
| ℹ️ Check |
|---|
| If this review is for the DODIN Backbone, mark as not applicable. Verify the router is configured to deny router-advertisements. apic1(config-tenant-fhs-secpol)# router-advertisement-guard If the router is not configured to reject outbound route advertisements for prefixes belonging to the IP core, this is a finding. |
| ✔️ Fix |
|---|
| Configure the router with FHS to suppress Router Advertisements on all external IPv6-enabled interfaces as shown in the example below. View the FHS requirement in the Layer 2 STIG. apic1(config-tenant-fhs-secpol)# router-advertisement-guard |