STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS Wireless Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

The network element must authenticate all network-connected endpoint devices before establishing any connection.

DISA Rule

SV-266632r1040624_rule

Vulnerability Number

V-266632

Group Title

SRG-NET-000343

Rule Version

ARBA-NT-000850

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

1. Navigate to Configuration >> Services >> VPN and expand "Site-to-Site".
2. Select the configured site-to-site VPN IPsec maps. Select the applicable Server certificate. Select the applicable trusted DOD root CA under "CA certificate:".
3. Click Submit >> Pending Changes >> Deploy Changes.
4. Navigate to Configuration >> Access Points >> Remote APs tab.
5. Select the check box next to the AP Name in the Remote AP table and click "Provision".
6. In the "General" tab, select "Certificate" from the "Authentication method:" drop-down list.
7. Click "Submit" to apply the configuration and reboot the AP as a certificate Remote AP.
8. Click Pending Changes >> Deploy Changes.

Check Contents

If the AP is not being used as a Remote AP, this check is not applicable.

Verify the AOS configuration with the following commands:

1. Site-to-site VPN:
show crypto-local ipsec-map

If a CA certificate and Server certificate are not configured for each IPsec map, this is a finding.

2. Hardware client VPN:
show "remote ap profile"

If certificate authentication is not configured for each RAP profile, this is a finding.

Vulnerability Number

V-266632

Documentable

False

Rule Version

ARBA-NT-000850

Severity Override Guidance

If the AP is not being used as a Remote AP, this check is not applicable.

Verify the AOS configuration with the following commands:

1. Site-to-site VPN:
show crypto-local ipsec-map

If a CA certificate and Server certificate are not configured for each IPsec map, this is a finding.

2. Hardware client VPN:
show "remote ap profile"

If certificate authentication is not configured for each RAP profile, this is a finding.

Check Content Reference

M

Target Key

5646