The BGP Cisco ACI must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-272080SRG-NET-000205-RTR-000006CACI-RT-000020SV-272080r1113986_rule2025-06-181
Description
Outbound route advertisements belonging to the core can result in traffic either looping or being black holed, or at a minimum, using a nonoptimized path.
ℹ️ Check
If this review is for the DODIN Backbone, mark as not applicable. Verify the router is configured to deny router-advertisements. apic1(config-tenant-fhs-secpol)# router-advertisement-guard If the router is not configured to reject outbound route advertisements for prefixes belonging to the IP core, this is a finding.
✔️ Fix
Configure the router with FHS to suppress Router Advertisements on all external IPv6-enabled interfaces as shown in the example below. View the FHS requirement in the Layer 2 STIG. apic1(config-tenant-fhs-secpol)# router-advertisement-guard