STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS Wireless Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

When AOS is used as a wireless local area network (WLAN) controller, WLAN Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) implementation must use certificate-based public key infrastructure (PKI) authentication to connect to DOD networks.

DISA Rule

SV-266703r1040640_rule

Vulnerability Number

V-266703

Group Title

SRG-NET-000070

Rule Version

ARBA-NT-001590

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

1. Navigate to Configuration >> Authentication.
2. Click the plus sign (+) under the "All Servers" field.
3. Add enterprise RADIUS servers by providing the Name and IP address/hostname.
4. Click on the added RADIUS server. Configure the Shared key.
5. Click Submit >> Pending Changes >> Deploy Changes.
6. Navigate to Configuration >> WLANs and select the desired WLAN in the "WLANs" field.
7. Under the selected WLAN, select "Security".
8. Click the plus sign (+) in the "Auth servers:" field and add the previously created enterprise RADIUS servers.
9. Click Submit >> Pending Changes >> Deploy Changes.

Check Contents

Verify the AOS configuration using the web interface:

1. Navigate to Configuration >> WLANs and select the desired WLAN in the WLANs field.
2. Under the selected WLAN, select "Security". Note which Auth servers are configured.
3. Navigate to Configuration >> Authentication.
4. In the "All Servers" field, select each WLAN authentication server noted earlier.
5. Verify each configured authentication server is configured to support EAP-TLS with DOD PKI.

If each WLAN authentication server is not configured to support EAP-TLS with DOD PKI, this is a finding.

Vulnerability Number

V-266703

Documentable

False

Rule Version

ARBA-NT-001590

Severity Override Guidance

Verify the AOS configuration using the web interface:

1. Navigate to Configuration >> WLANs and select the desired WLAN in the WLANs field.
2. Under the selected WLAN, select "Security". Note which Auth servers are configured.
3. Navigate to Configuration >> Authentication.
4. In the "All Servers" field, select each WLAN authentication server noted earlier.
5. Verify each configured authentication server is configured to support EAP-TLS with DOD PKI.

If each WLAN authentication server is not configured to support EAP-TLS with DOD PKI, this is a finding.

Check Content Reference

M

Target Key

5646