STIGQter STIGQter: STIG Summary:

HPE Aruba Networking AOS Wireless Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-266557r1040161_ruleAOS must use Transport Layer Security (TLS) 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
SV-266559r1040167_ruleAOS must protect wireless access to the network using authentication of users and/or devices.
SV-266560r1040170_ruleThe network element must protect wireless access to the system using Federal Information Processing Standard (FIPS)-validated Advanced Encryption Standard (AES) block cipher algorithms with an approved confidentiality mode.
SV-266577r1040221_ruleAOS must be configured to disable nonessential capabilities.
SV-266591r1040263_ruleAOS must manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks.
SV-266627r1173879_ruleAOS must require devices to reauthenticate when organization-defined circumstances or situations requiring reauthentication.
SV-266632r1040624_ruleThe network element must authenticate all network-connected endpoint devices before establishing any connection.
SV-266639r1117244_ruleAOS must use cryptographic algorithms approved by the National Security Agency (NSA) to protect national security systems (NSS) when transporting classified traffic across an unclassified network.
SV-266644r1040422_ruleAOS, in conjunction with a remote device, must prevent the device from simultaneously establishing nonremote connections with the system and communicating via some other connection to resources in external networks.
SV-266703r1040640_ruleWhen AOS is used as a wireless local area network (WLAN) controller, WLAN Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) implementation must use certificate-based public key infrastructure (PKI) authentication to connect to DOD networks.
SV-266704r1192887_ruleThe site must conduct continuous wireless Intrusion Detection System (IDS) scanning.
SV-266705r1040645_ruleAOS, when configured as a WLAN bridge, must not be configured to have any feature enabled that calls home to the vendor.
SV-266707r1040611_ruleAOS, when used as a WLAN bridge or controller, must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface.
SV-266708r1040614_ruleAOS wireless local area network (WLAN) service set identifiers (SSIDs) must be changed from the manufacturer's default to a pseudo random word that does not identify the unit, base, organization, etc.