STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

DISA Rule

SV-266928r1039805_rule

Vulnerability Number

V-266928

Group Title

SRG-APP-000142-NDM-000245

Rule Version

ARBA-ND-000245

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
firewall cp
ipv4 deny any proto 6 ports 17 17
ipv4 deny any proto 6 ports 8080 8080
ipv4 deny any proto 6 ports 8081 8081
ipv4 deny any proto 6 ports 8082 8082
ipv4 deny any proto 6 ports 8088 8088
ipv6 deny any proto 6 ports 17 17
ipv6 deny any proto 6 ports 8080 8080
ipv6 deny any proto 6 ports 8081 8081
ipv6 deny any proto 6 ports 8082 8082
ipv6 deny any proto 6 ports 8088 8088
exit
write memory

For any OSPF entries found:
no router ospf
no router ospf router-id <IP address>
no router ospf redistribute vlan <#>
no <any other ospf entries>
write memory

Block any other ports as desired using the following example:
configure terminal
firewall cp
<ipv4/ipv6> deny any proto <ftp, http, telnet, tftp, protocol #> ports <start port 0-65535> <end port 0-65535>
exit
write memory

Check Contents

Verify the AOS configuration with the following commands:
show firewall-cp
show running-config | include ospf

Verify that OSPF is not enabled and only unnecessary and/or nonsecure functions, ports, protocols, and/or services are denied.

If OSPF is enabled or any unnecessary and/or nonsecure functions, ports, protocols, and/or services are allowed, this is a finding.

Vulnerability Number

V-266928

Documentable

False

Rule Version

ARBA-ND-000245

Severity Override Guidance

Verify the AOS configuration with the following commands:
show firewall-cp
show running-config | include ospf

Verify that OSPF is not enabled and only unnecessary and/or nonsecure functions, ports, protocols, and/or services are denied.

If OSPF is enabled or any unnecessary and/or nonsecure functions, ports, protocols, and/or services are allowed, this is a finding.

Check Content Reference

M

Target Key

5648