First Hop Security - Router Advertisement Guard - Admin Status

Information

Router Advertisement Guard administrative status. The RA Guard allows the network administrator to block or reject unwanted or rogue router advertisement (RA) and Redirect messages that arrive at the network device platform. The status can be:
- Disable
- Enable

The default is Enable.

Solution

Log into the Cisco APIC Web Console:
Navigate to 'Tenants'

Repeat the following for all tenants:

- Double click the tenant

- Expand the tenant

- Expand 'Policies'

- Expand 'Protocol'

- Expand 'First Hop Secuirty'

- Expand 'Feature Policies'

- For each policy, in the 'RA Guard' section, ensure 'Admin Status' is set to 'Enable'

Item Details

Audit Name: Tenable Cisco ACI

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Cisco_ACI

Control ID: 7197c6edba9081b6ac5292fd7c93a16a8ba5cbd0b973be8473e7c3629263f198