STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS Wireless Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

AOS, in conjunction with a remote device, must prevent the device from simultaneously establishing nonremote connections with the system and communicating via some other connection to resources in external networks.

DISA Rule

SV-266644r1040422_rule

Vulnerability Number

V-266644

Group Title

SRG-NET-000369

Rule Version

ARBA-NT-000970

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

1. Navigate to Configuration >> System >> Profiles.
2. Under "All Profiles", expand "Virtual AP".
3. Select each Virtual AP profile. Under "General", select tunnel as the Forward mode.
4. Click Submit >> Pending Changes >> Deploy Changes.
5. In configuration mode (CLI), for each ap system-profile, run the following commands:
ap system-profile <profile-name>
double-encrypt
exit
write memory

Check Contents

Verify the AOS configuration with the following commands:
show running-configuration | include split-tunnel
show running-config | include double-encrypt

If any instances of forward-mode split-tunnel are found or if double-encrypt is not enabled, this is a finding.

Vulnerability Number

V-266644

Documentable

False

Rule Version

ARBA-NT-000970

Severity Override Guidance

Verify the AOS configuration with the following commands:
show running-configuration | include split-tunnel
show running-config | include double-encrypt

If any instances of forward-mode split-tunnel are found or if double-encrypt is not enabled, this is a finding.

Check Content Reference

M

Target Key

5646