STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

The Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period.

DISA Rule

SV-266996r1040892_rule

Vulnerability Number

V-266996

Group Title

SRG-NET-000213-VPN-000721

Rule Version

ARBA-VN-000721

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:

For each VIA authentication profile:
aaa authentication via connection-profile

configure terminal
aaa authentication via
connection-profile<name>
max-timeout value <0-65535>
exit
write memory

Check Contents

Verify the AOS configuration with the following commands:
show aaa authentication via connection-profile

Note each referenced VIA connection profile.

For each referenced connection profile:
show aaa authentication via connection-profile <name> | include "VIA max session timeout"

If the max session timeout is not set to the organization-defined time, this is a finding.

Vulnerability Number

V-266996

Documentable

False

Rule Version

ARBA-VN-000721

Severity Override Guidance

Verify the AOS configuration with the following commands:
show aaa authentication via connection-profile

Note each referenced VIA connection profile.

For each referenced connection profile:
show aaa authentication via connection-profile <name> | include "VIA max session timeout"

If the max session timeout is not set to the organization-defined time, this is a finding.

Check Content Reference

M

Target Key

5645