STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS Wireless Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

AOS must be configured to disable nonessential capabilities.

DISA Rule

SV-266577r1040221_rule

Vulnerability Number

V-266577

Group Title

SRG-NET-000131

Rule Version

ARBA-NT-000300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
firewall cp
ipv4 deny any proto 6 ports 17 17 ipv4 deny any proto 6 ports 8080 8080
ipv4 deny any proto 6 ports 8081 8081
ipv4 deny any proto 6 ports 8082 8082
ipv4 deny any proto 6 ports 8088 8088
ipv6 deny any proto 6 ports 17 17
ipv6 deny any proto 6 ports 8080 8080
ipv6 deny any proto 6 ports 8081 8081
ipv6 deny any proto 6 ports 8082 8082
ipv6 deny any proto 6 ports 8088 8088
exit
write memory

Block any other ports as desired using the following example:
<ipv4/ipv6> deny any proto <ftp, http, telnet, tftp, protocol #> ports <start port 0-65535> <end port 0-65535>

Check Contents

Verify the AOS configuration with the following command:
show firewall-cp

Verify that nonessential capabilities, functions, ports, protocols, and/or services are denied.

If any nonessential capabilities, functions, ports, protocols, and/or services are allowed, this is a finding.

Vulnerability Number

V-266577

Documentable

False

Rule Version

ARBA-NT-000300

Severity Override Guidance

Verify the AOS configuration with the following command:
show firewall-cp

Verify that nonessential capabilities, functions, ports, protocols, and/or services are denied.

If any nonessential capabilities, functions, ports, protocols, and/or services are allowed, this is a finding.

Check Content Reference

M

Target Key

5646