Management Access Policy - SSH - MACs - hmac-sha1

Information

The state of the 'hmac-sha1' MAC (Message Authentication Code) algorithm(s) used for data integrity verification. The state can be:
- Enabled
- Disabled

Solution

Log into the Cisco APIC Web Console:
Navigate to 'Fabric' -> 'Fabric Policies'.

Click 'Fabric Security'.

Expand 'Policies'

Expand 'Pod'

Expand 'Management Access'

For each 'Management Access' policy, in the 'SSH' section, ensure 'MACs - hmac-sha1' is not checked.

Item Details

Audit Name: Tenable Cisco ACI

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Cisco_ACI

Control ID: 5457a0e8cf6fc5030c5728ca1ea13fac159b51dc0971fa70ac832182d3ec7049