Check: CACI-L2-000007
Cisco ACI Layer 2 Switch STIG:
CACI-L2-000007
(in version v1 r0.1)
Title
The Cisco ACI layer 2 switch must have IP Source Guard enabled on all user-facing or untrusted access switch ports. (Cat II impact)
Discussion
IP Source Guard provides source IP address filtering on a layer 2 port to prevent a malicious host from impersonating a legitimate host by assuming the legitimate host's IP address. The feature uses dynamic DHCP snooping and static IP source binding to match IP addresses to hosts on untrusted layer 2 access ports. Initially, all IP traffic on the protected port is blocked except for DHCP packets. After a client receives an IP address from the DHCP server, or after static IP source binding is configured by the administrator, all traffic with that IP source address is permitted from that client. Traffic from other hosts is denied. This filtering limits a host's ability to attack the network by claiming a neighbor host's IP address.
Check Content
In the Cisco APIC GUI, navigate to Tenants and repeat the following steps for all tenants: 1. On the menu bar, click Tenants >> Tenant_name. 2. In the Navigation pane, click Policies >> Protocol >> First Hop Security. 3. Expand Feature Policy and verify Source Guard is enabled and for both IPv4 and IPv6. If the switch does not have Source Guard-enabled user-facing or untrusted access switch ports, this is a finding.
Fix Text
In the Cisco APIC GUI, navigate to Tenants and repeat the following steps for all tenants: 1. On the menu bar, click Tenants >> Tenant_name. 2. In the Navigation pane, click Policies >> Protocol >> First Hop Security. 3. Right-click "First Hop Security" to open Create Feature Policy and fill out the form. - Check the "Source Guard" option box. - Enable for both IPv4 and IPv6. 4. Click "Submit".
Additional Identifiers
Rule ID: SV-272035r1064438_rule
Vulnerability ID: V-272035
Group Title: SRG-NET-000362-L2S-000026
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002385 |
Protect against or limit the effects of organization-defined types of denial-of-service events. |
Controls
Number | Title |
---|---|
SC-5 |
Denial of Service Protection |