Remote user login policy

Information

The default role policy for the remote user with invalid (or no) CiscoAVPairs returned by the AAA server. CiscoAVPairs provide support for Remote Access Dial-In User Service attribute-value (AV) pairs. The options are:
- Assign Default Role
- No Login

The default is No Login.

Solution

Log into the Cisco APIC Web Console:
Navigate to 'Admin' -> 'AAA' -> 'Authentication'

In the 'Properties' section ensure 'Remote user login policy' is not set to 'Assign Default Role'

Item Details

Audit Name: Tenable Cisco ACI

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Cisco_ACI

Control ID: c76f7a2ce3586b3d9d0dbc72997d48d24dabdc587457ec46db0b2f7793966b64