STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as a VPN Gateway, must terminate all network connections associated with a communications session at the end of the session.

DISA Rule

SV-266990r1040736_rule

Vulnerability Number

V-266990

Group Title

SRG-NET-000213-VPN-000720

Rule Version

ARBA-VN-000720

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
crypto-local isakmp dpd idle-timeout <idle_sec> retry-timeout <retry_sec> retry-attempts <retry_number>
write memory

Check Contents

Verify the AOS configuration with the following command:
show configuration effective | include dpd

If DPD is not configured, this is a finding.

Vulnerability Number

V-266990

Documentable

False

Rule Version

ARBA-VN-000720

Severity Override Guidance

Verify the AOS configuration with the following command:
show configuration effective | include dpd

If DPD is not configured, this is a finding.

Check Content Reference

M

Target Key

5645