STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS must be configured to enforce the limit of three consecutive invalid login attempts, after which time it must block any login attempt for 15 minutes.

DISA Rule

SV-266911r1039754_rule

Vulnerability Number

V-266911

Group Title

SRG-APP-000065-NDM-000214

Rule Version

ARBA-ND-000214

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
aaa password-policy mgmt
password-lock-out 3
password-lock-out-time 15
enable
exit
write memory

Check Contents

1. Verify the AOS configuration with the following command:
show aaa password-policy mgmt

2. Verify that "Maximum Number of failed attempts in 3 minute window to lockout password based user" is set to "3 attempts" and "Time duration to lockout the password based user upon crossing the 'lock-out' threshold" is set to "15 minutes".

If one or both of these settings are set to any other value, this is a finding.

Vulnerability Number

V-266911

Documentable

False

Rule Version

ARBA-ND-000214

Severity Override Guidance

1. Verify the AOS configuration with the following command:
show aaa password-policy mgmt

2. Verify that "Maximum Number of failed attempts in 3 minute window to lockout password based user" is set to "3 attempts" and "Time duration to lockout the password based user upon crossing the 'lock-out' threshold" is set to "15 minutes".

If one or both of these settings are set to any other value, this is a finding.

Check Content Reference

M

Target Key

5648