First Hop Security - IP Inspection - Admin Status

Information

The IP Inspection administrative status. IP Inspection learns and secures bindings for stateless and stateful auto-configuration addresses in Layer 2 neighbor tables. The status can be:
- Disable
- Enable Both IPv4 and IPv6

The default is Enable Both IPv4 and IPv6.

Solution

Log into the Cisco APIC Web Console:
Navigate to 'Tenants'

Repeat the following for all tenants:

- Double click the tenant

- Expand the tenant

- Expand 'Policies'

- Expand 'Protocol'

- Expand 'First Hop Secuirty'

- Expand 'Feature Policies'

- For each policy, in the 'IP Inspection' section, ensure 'Admin Status' is set to 'Enable Both IPv4 and IPv6'

Item Details

Audit Name: Tenable Cisco ACI

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Cisco_ACI

Control ID: 2edc24925d68ca1a961fb1fb03aad0d36834534696b45410b1276eb8918b5008