STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Cisco ACI Layer 2 Switch Security Technical Implementation Guide

V-272037

CAT II (Medium)

The Cisco ACI layer 2 switch must enable port security.

Rule ID

SV-272037r1168273_rule

STIG

Cisco ACI Layer 2 Switch Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-002385

Discussion

The port security feature protects the ACI fabric from being flooded with unknown MAC addresses by limiting the number of MAC addresses learned per port. The port security feature support is available for physical ports, port channels, and virtual port channels.

Check Content

Review the port security policies for compliance. Navigate to Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >>Policy Groups >> (Leaf Access port, PC interface or VPC interface) >> {{your_policy_name}} >> Advance Policies.

Select each port security policy used and verify the following:
- Port Security Timeout is set to "600 seconds".
- Violation Action is set to "Protect mode".
- Maximum Endpoints is set to "1".

Verify port security is active on all appropriate host-facing interfaces. Verify each leaf has been configured to use a correctly configured port security policy.

If port security is not configured and enabled, this is a finding.

Fix Text

Create a port security policy. The port security policy can be created new or chosen from the list of available port security policies.

Path to use Port Security setting: Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >>Policy Groups >> (Leaf Access port, PC interface or VPC interface) >> {{your_policy_name}} >> Advance Policies.

If the Policy group is not on the Appropriate interface, navigate to the following to add it:
Fabric >> Access Policies >> Interfaces >> Leaf Interfaces >> Profiles >> {{your_profile}}

In the Create Port Security Policy dialog box:
1. In the Port Security Timeout field, enter "600" before re-enabling MAC learning on an interface.
2. In the Maximum Endpoints field, enter "1" for the maximum number of endpoints that can be learned on an interface.
3. In the Violation Action field, select "Protect". 
4. Click "Submit".