HPE Aruba Networking AOS NDM Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
Digest of Updates ✎ 9
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Content changes 9
- V-266909 High description AOS must be configured to assign appropriate user roles or access levels to authenticated users.
- V-266912 Medium descriptioncheck AOS must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the device.
- V-266913 Medium description AOS must retain the Standard Mandatory DoW Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log on for further access.
- V-266929 High descriptionfix AOS must be configured to use DoW public key infrastructure (PKI) as multifactor authentication (MFA) for interactive logins.
- V-266938 High description AOS must be configured to use DoW-approved Online Certificate Status Protocol (OCSP) responders or Certificate Revocation Lists (CRLs) to validate certificates used for public key infrastructure (PKI)-based authentication.
- V-266940 High description AOS must use FIPS 140-2/140-3 approved algorithms for authentication to a cryptographic module.
- V-266953 Medium description AOS must be configured to synchronize internal information system clocks using redundant authoritative time sources.
- V-266961 Medium description AOS must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
- V-266973 Medium fix AOS must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- ARBA-ND-000200
- Vuln IDs
-
- V-266903
- Rule IDs
-
- SV-266903r1039730_rule
Checks: C-70827r1039728_chk
Verify the AOS configuration with the following command: show mgmt-user admin If "Max-concurrent-sessions" is not set to "3", this is a finding.
Fix: F-70730r1039729_fix
Configure AOS with the following commands: configure terminal mgmt-user admin root max-concurrent-sessions 3 Enter the admin's password Reenter the admin's password write memory
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- ARBA-ND-000208
- Vuln IDs
-
- V-266908
- Rule IDs
-
- SV-266908r1039745_rule
Checks: C-70832r1039743_chk
Verify the AOS configuration with the following command: show logging level If the security logging level is not set to debug, this is a finding.
Fix: F-70735r1039744_fix
Configure AOS with the following commands: configure terminal logging security level debug write memory
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- ARBA-ND-000212
- Vuln IDs
-
- V-266909
- Rule IDs
-
- SV-266909r1264014_rule
Checks: C-70833r1264012_chk
Verify the AOS configuration using the web interface: Navigate to Configuration >> System >> Admin tab and expand the "Admin Authentication Options". If root is not the Default role, "Enable" is not checked, or the Server group is not configured to the enterprise server group for admin authorization, this is a finding.
Fix: F-70736r1264013_fix
Configure AOS using the web interface: Navigate to Configuration >> System >> Admin tab and expand the "Admin Authentication Options". Select root for the Default role. Check the "Enable" checkbox. Select the enterprise Server group that is configured for admin authorization. Click Submit >> Pending Changes >> Deploy changes.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- ARBA-ND-000213
- Vuln IDs
-
- V-266910
- Rule IDs
-
- SV-266910r1039751_rule
Checks: C-70834r1039749_chk
Verify the AOS configuration with the following command: show running-config | begin "interface gigabit" Note the configured IP access-group session Access Control List (ACL) for each active interface. For each configured ACL: show ip access-list <ACL name> If each ACL does not end in an "any any deny log" for both IPv4 and IPv6, this is a finding.
Fix: F-70737r1039750_fix
Configure AOS with the following commands: configure terminal ip access-list session <name> network <A.B.C.D> <netmask A.B.C.D> any any permit any any any deny log ipv6 network <X:X:X:X::X/<0-128> any any permit ipv6 any any any deny log exit write memory interface gigabit <#/#/#> ip access-group session <ACL name> exit write mem
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- ARBA-ND-000214
- Vuln IDs
-
- V-266911
- Rule IDs
-
- SV-266911r1039754_rule
Checks: C-70835r1039752_chk
1. Verify the AOS configuration with the following command: show aaa password-policy mgmt 2. Verify that "Maximum Number of failed attempts in 3 minute window to lockout password based user" is set to "3 attempts" and "Time duration to lockout the password based user upon crossing the 'lock-out' threshold" is set to "15 minutes". If one or both of these settings are set to any other value, this is a finding.
Fix: F-70738r1039753_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt password-lock-out 3 password-lock-out-time 15 enable exit write memory
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- ARBA-ND-000215
- Vuln IDs
-
- V-266912
- Rule IDs
-
- SV-266912r1264016_rule
Checks: C-70836r1264015_chk
Verify the AOS configuration with the following command: show banner If the Standard Mandatory DoW Notice and Consent Banner is not set, this is a finding.
Fix: F-70739r1039756_fix
Configure AOS with the following commands: configure terminal banner motd # You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.# write memory
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- ARBA-ND-000216
- Vuln IDs
-
- V-266913
- Rule IDs
-
- SV-266913r1264017_rule
Checks: C-70837r1039758_chk
Verify the AOS configuration with the following command: show running-config | include "banner enforce-accept" If "banner enforce-accept" is not set, this is a finding.
Fix: F-70740r1039759_fix
Configure AOS with the following commands: configure terminal banner enforce-accept write memory
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000382
- Version
- ARBA-ND-000245
- Vuln IDs
-
- V-266928
- Rule IDs
-
- SV-266928r1043177_rule
Checks: C-70852r1039803_chk
Verify the AOS configuration with the following commands: show firewall-cp show running-config | include ospf Verify that OSPF is not enabled and only unnecessary and/or nonsecure functions, ports, protocols, and/or services are denied. If OSPF is enabled or any unnecessary and/or nonsecure functions, ports, protocols, and/or services are allowed, this is a finding.
Fix: F-70755r1039804_fix
Configure AOS with the following commands: configure terminal firewall cp ipv4 deny any proto 6 ports 17 17 ipv4 deny any proto 6 ports 8080 8080 ipv4 deny any proto 6 ports 8081 8081 ipv4 deny any proto 6 ports 8082 8082 ipv4 deny any proto 6 ports 8088 8088 ipv6 deny any proto 6 ports 17 17 ipv6 deny any proto 6 ports 8080 8080 ipv6 deny any proto 6 ports 8081 8081 ipv6 deny any proto 6 ports 8082 8082 ipv6 deny any proto 6 ports 8088 8088 exit write memory For any OSPF entries found: no router ospf no router ospf router-id <IP address> no router ospf redistribute vlan <#> no <any other ospf entries> write memory Block any other ports as desired using the following example: configure terminal firewall cp <ipv4/ipv6> deny any proto <ftp, http, telnet, tftp, protocol #> ports <start port 0-65535> <end port 0-65535> exit write memory
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- ARBA-ND-000247
- Vuln IDs
-
- V-266929
- Rule IDs
-
- SV-266929r1264019_rule
Checks: C-70853r1039806_chk
Verify the AOS configuration using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Options". 2. Verify what "Server group" is handling admin authentication. 3. Verify that Client certificate is enabled. 4. Expand "Admin Authentication Servers". 5. Select the Server Group identified from the "Options" section. 6. Verify that each authentication server configured in Server Group <server group name> is configured with the Key attribute: of userPrincipalName. If Client certificate is not enabled and the management authentication servers are not configured with userPrincipalName, this is a finding.
Fix: F-70756r1264018_fix
Configure AOS using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Servers". 2. Click on the plus sign (+) under "All Servers" and configure the type of authentication server. Provide the Name, Type, and IP address. Click "Submit". 3. Select the created authentication server and configure the required attributes for LDAP: Admin-dn <username> Admin-passwd <password> Re-type admin-passwd <password> Auth port: 636 Base-dn: cn/ou=<container>,dc=<level>,dc=<mil> Key-attribute: userPrincipalName 4. Click "Submit." 5. Repeat this process and configure a second authentication server. 6. Click "Pending Changes" and then "Deploy changes". 7. Click on the plus sign (+) under "Server Groups" and add a server group. 8. Click "Submit". 9. Select the created server group and click the plus sign (+) in the Server Group <server group name> box. 10. Add the first configured authentication server. 11. Reselect the created server group and click the plus sign (+) in the Server Group <server group name> box. 12. Click Submit >> Pending Changes >> Deploy Changes. 13. Navigate to Management User. 14. Click on "Show users with certificate authentication". Click on the plus sign (+). 15. Configure each Trusted CA certificate name for any DoW Root CA that provides trust for admin users. 16. Select External server for the Authentication server. 17. Click Submit >> Pending Changes >> Deploy Changes. 18. Expand "Admin Authentication Options". Check "Enable" and "Client certificate". Select the Server group created earlier. 19. Click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- ARBA-ND-000250
- Vuln IDs
-
- V-266930
- Rule IDs
-
- SV-266930r1039811_rule
Checks: C-70854r1039809_chk
Verify the AOS configuration using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Options". 2. Verify what "Server group" is handling admin authentication. 3. Expand "Admin Authentication Servers". 4. Select the Server Group identified from the "Options" section. 5. Verify that each authentication server configured in Server Group <server group name> is configured with secure LDAP using port 636 and connection type ldap-s. If each management authentication server is not configured to use secure LDAP, this is a finding.
Fix: F-70757r1039810_fix
Configure AOS using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Servers". 2. Click on the plus sign (+) under "All Servers" and configure the type of authentication server. Provide the Name, Type, and IP address. Click "Submit". 3. Select the created authentication server and configure the required attributes for LDAP: Admin-dn <username> Admin-passwd <password> Re-type admin-passwd <password> Auth port: 636 Base-dn: cn/ou=<container>,dc=<level>,dc=<mil> Key-attribute: userPrincipalName 4. Click "Submit". 5. Repeat this process and configure a second authentication server. 6. Click Pending Changes >> Deploy Changes. 7. Click on the plus sign (+) under "Server Groups" and add a server group. Click "Submit". 8. Select the created server group and click the plus sign (+) in the Server Group <server group name> box. 9. Add the first configured authentication server. 10. Reselect the created server group and click the plus sign (+) in the Server Group <server group name> box. 11. Click Submit >> Pending Changes >> Deploy Changes. 12. Expand "Admin Authentication Options". Select the Server group created earlier. 13. Click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- ARBA-ND-000252
- Vuln IDs
-
- V-266931
- Rule IDs
-
- SV-266931r1039814_rule
Checks: C-70855r1039812_chk
Verify the AOS configuration with the following command: show aaa password-policy mgmt If "Minimum password length required" is not set to "15 characters", this is a finding.
Fix: F-70758r1039813_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt password-min-length 15 exit write memory
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- ARBA-ND-000254
- Vuln IDs
-
- V-266932
- Rule IDs
-
- SV-266932r1039817_rule
Checks: C-70856r1039815_chk
Verify the AOS configuration with the following command: show aaa password-policy mgmt If "Minimum number of Upper Case characters" is not set to "1 characters", this is a finding.
Fix: F-70759r1039816_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt password-min-uppercase-characters 1 exit write memory
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- ARBA-ND-000255
- Vuln IDs
-
- V-266933
- Rule IDs
-
- SV-266933r1039820_rule
Checks: C-70857r1039818_chk
Verify the AOS configuration with the following command: show aaa password-policy mgmt If "Minimum number of Lower Case characters" is not set to "1 characters", this is a finding.
Fix: F-70760r1039819_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt password-min-lowercase-characters 1 exit write memory
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- ARBA-ND-000256
- Vuln IDs
-
- V-266934
- Rule IDs
-
- SV-266934r1039823_rule
Checks: C-70858r1039821_chk
Verify the AOS configuration with the following command: show aaa password-policy mgmt If "Minimum number of Digits" is not set to "1 digits", this is a finding.
Fix: F-70761r1039822_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt password-min-digit 1 exit write memory
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001619
- Version
- ARBA-ND-000257
- Vuln IDs
-
- V-266935
- Rule IDs
-
- SV-266935r1039826_rule
Checks: C-70859r1039824_chk
Verify the AOS configuration with the following command: show aaa password-policy mgmt If "Minimum number of Special characters" is not set to "1 characters", this is a finding.
Fix: F-70762r1039825_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt password-min-special-character 1 exit write memory
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000197
- Version
- ARBA-ND-000259
- Vuln IDs
-
- V-266937
- Rule IDs
-
- SV-266937r1039832_rule
Checks: C-70861r1039830_chk
Verify the AOS configuration with the following commands: show aaa authentication-server all show snmp user-table If the LDAP servers are not configured to use port 636, or if the SNMP users are not configured to use AES encryption, this is a finding.
Fix: F-70764r1039831_fix
Configure AOS with the following commands: configure terminal aaa authentication-server ldap <server name> authport 636 preferred-conn-type ldap-s exit snmp-server user <username> auth-prot sha <passphrase> priv-prot AES <passphrase> write memory
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000185
- Version
- ARBA-ND-000262
- Vuln IDs
-
- V-266938
- Rule IDs
-
- SV-266938r1264020_rule
Checks: C-70862r1039833_chk
Verify the AOS configuration with the following command: show crypto-local pki rcp If any configured trusted root certificate authorities are not configured to use OCSP, this is a finding.
Fix: F-70765r1039834_fix
Configure AOS using the web interface: 1. Navigate to Configuration >> System >> Certificates tab. 2. Under "Import Certificates", upload the trusted root CA. Provide the Certificate name, upload the certificate file, and select the matching Certificate format. 3. Choose the TrustedCA Certificate type. Click "Submit". 4. Upload the same certificate and select the OCSPResponderCert Certificate type (provide a different friendly name). Click "Submit". 5. Click Pending Changes >> Deploy the Changes. 6. Expand "Revocation Checkpoint". Select the configured trusted root CA. 7. Select OCSP for Revocation method 1. 8. Enter the OCSP server URL in the OCSP URL field (remove "http://"). 9. Choose the configured certificate under OCSP responder cert. 10. Choose "Fail-Over" for Server unreachable. 11. Click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- IA-7
- Severity
- H
- CCI
- CCI-000803
- Version
- ARBA-ND-000265
- Vuln IDs
-
- V-266940
- Rule IDs
-
- SV-266940r1264021_rule
Checks: C-70864r1039839_chk
Verify the AOS configuration with the following command: show fips If "FIPS settings: Mode Enabled" is not returned, this is a finding.
Fix: F-70767r1039840_fix
Configure AOS with the following commands: configure terminal fips enable write memory reload
- RMF Control
- SC-10
- Severity
- H
- CCI
- CCI-001133
- Version
- ARBA-ND-000267
- Vuln IDs
-
- V-266941
- Rule IDs
-
- SV-266941r1039844_rule
Checks: C-70865r1039842_chk
Verify the AOS configuration with the following commands: show running-config | include "loginsession timeout" show web-server profile If the login session timeout is not set to "5" (minutes), this is a finding. If "User session timeout <30-3600> (seconds)" is not set to "300", this is a finding.
Fix: F-70768r1039843_fix
Configure AOS with the following commands: configure terminal loginsession timeout 5 web-server profile session-timeout 300 exit write memory
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- ARBA-ND-000287
- Vuln IDs
-
- V-266948
- Rule IDs
-
- SV-266948r1137878_rule
Checks: C-70872r1039863_chk
Verify the AOS configuration using the web interface: 1. Navigate to Configuration >> System >> Admin. Expand "Admin Authentication Options". 2. Verify the following: - Default role: Is set to root. - Enable: Checkbox is checked. - The enterprise Server group is set to the configured enterprise LDAP server group. If any of the three settings above are not configured, this is a finding.
Fix: F-70775r1039864_fix
Configure AOS using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Options". 2. Select the Default role: of root. 3. Click the Enable: checkbox. 4. Select the configured enterprise LDAP server group. 5. Under Server group, click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002234
- Version
- ARBA-ND-000289
- Vuln IDs
-
- V-266950
- Rule IDs
-
- SV-266950r1039871_rule
Checks: C-70874r1039869_chk
Verify the AOS configuration with the following command: show running-config | include audit-trail If the audit-trail is not enabled, this is a finding.
Fix: F-70777r1039870_fix
Configure AOS with the following commands: configure terminal audit-trail all write memory
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001858
- Version
- ARBA-ND-000295
- Vuln IDs
-
- V-266952
- Rule IDs
-
- SV-266952r1039877_rule
Checks: C-70876r1039875_chk
Verify the AOS configuration with the following commands: show snmp trap-hosts show snmp trap-list | include wlsxProcessDied show snmp trap-list | include wlsxProcessRestart If a SNMP server is not configured and both process traps are not enabled, this is a finding.
Fix: F-70779r1039876_fix
Configure AOS with the following commands: configure terminal snmp-server host <IPv4 or IPv6 address> version <SNMP version> snmp-server host <IPv4 or IPv6 address> version <SNMP version> <SNMPv3 username> engine-id <SNMP engine ID> snmp-server trap wlsxProcessDied snmp-server trap wlsxProcessRestart write memory
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- ARBA-ND-000298
- Vuln IDs
-
- V-266953
- Rule IDs
-
- SV-266953r1264022_rule
Checks: C-70877r1039878_chk
Verify the AOS configuration with the following command: show ntp servers If at least two NTP servers are not configured, this is a finding.
Fix: F-70780r1039879_fix
Configure AOS with the following commands: configure terminal ntp authentication-key (keyid #> sha1 <plaintext key> ntp trusted-key <keyid #> ntp server <first fqdn, ipv4, or ipv6 address> key <keyid #> ntp server <second fqdn, ipv4, or ipv6 address> key <keyid #> ntp authenticate write memory
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-001890
- Version
- ARBA-ND-000299
- Vuln IDs
-
- V-266954
- Rule IDs
-
- SV-266954r1039962_rule
Checks: C-70878r1039881_chk
Verify the AOS configuration with the following command: show clock If the clock is not set to the appropriate time zone or UTC/GMT, this is a finding.
Fix: F-70781r1039962_fix
Configure AOS with the following commands: configure terminal clock timezone <IANA time zone> to set the appropriate timezone write memory
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- ARBA-ND-000310
- Vuln IDs
-
- V-266958
- Rule IDs
-
- SV-266958r1039895_rule
Checks: C-70882r1039893_chk
Verify the AOS configuration with the following command: show snmp user-table If the configured SNMP user(s) are not using SHA, this is a finding.
Fix: F-70785r1039894_fix
Configure AOS with the following commands: configure terminal snmp-server user <SNMP user> auth-prot sha <authentication password> priv-prot aes <privacy password> write memory
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-002007
- Version
- ARBA-ND-000313
- Vuln IDs
-
- V-266959
- Rule IDs
-
- SV-266959r1039898_rule
Checks: C-70883r1039896_chk
Verify the AOS configuration with the following command: show configuration effective | include auth-survivability If "aaa auth-survivability enable" is returned and "auth-survivability" is enabled, this is a finding.
Fix: F-70786r1039897_fix
Configure AOS with the following commands: configure terminal no aaa auth-survivability enable write memory
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- ARBA-ND-000315
- Vuln IDs
-
- V-266961
- Rule IDs
-
- SV-266961r1264023_rule
Checks: C-70885r1039902_chk
Verify the AOS configuration using the web interface: Navigate to Configuration >> Services >> Firewall. If the organization-defined safeguards are not enabled to protect against known DoS attacks, this is a finding.
Fix: F-70788r1039903_fix
Configure AOS using the web interface: Navigate to Configuration >> Services >> Firewall and enable DoS protection in accordance with organization-defined policy. Click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- ARBA-ND-000325
- Vuln IDs
-
- V-266966
- Rule IDs
-
- SV-266966r1039919_rule
Checks: C-70890r1039917_chk
Verify the AOS configuration with the following command: show logging server If a configured syslog server is not returned, this is a finding.
Fix: F-70793r1039918_fix
Configure AOS with the following commands: configure terminal logging <IPv4 or IPv6 address> write memory
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000195
- Version
- ARBA-ND-000329
- Vuln IDs
-
- V-266967
- Rule IDs
-
- SV-266967r1043189_rule
Checks: C-70891r1039961_chk
Verify the AOS configuration with the following command: show aaa password-policy mgmt If "Minimum number of differing characters between passwords" is not set to "8 digits", this is a finding.
Fix: F-70794r1039921_fix
Configure AOS with the following commands: configure terminal aaa password-policy mgmt min-char-difference 8 exit write memory
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- ARBA-ND-000334
- Vuln IDs
-
- V-266968
- Rule IDs
-
- SV-266968r1207743_rule
Checks: C-70892r1039923_chk
Verify the AOS configuration with the following command: show logging level If the logging levels are not set to the organization-desired level, this is a finding.
Fix: F-70795r1039924_fix
Configure AOS with the following commands for each logging category: configure terminal logging <category> level <level> write memory
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000370
- Version
- ARBA-ND-000336
- Vuln IDs
-
- V-266970
- Rule IDs
-
- SV-266970r1137887_rule
Checks: C-70894r1039929_chk
Verify the AOS configuration using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Options". 2. Verify what "Server group" is handling admin authentication. 3. Expand "Admin Authentication Servers". 4. Select the Server Group identified from the "Options" section. 5. Verify that at least two authentication servers are configured in the Server Group. If the admin authentication server group does not have at least two configured authentication servers, this is a finding.
Fix: F-70797r1039930_fix
Configure AOS using the web interface: 1. Navigate to Configuration >> System >> Admin and expand "Admin Authentication Servers". 2. Click on the plus sign (+) under "All Servers" and configure the type of authentication server. Provide the Name, Type, and IP address. Click "Submit". 3. Select the created authentication server and configure the required attributes for LDAP: Admin-dn <username> Admin-passwd <password> Re-type admin-passwd <password> Auth port: 636 Base-dn: cn/ou=<container>,dc=<level>,dc=<mil> Key-attribute: userPrincipalName 4. Click "Submit". 5. Repeat this process and configure a second authentication server. 6. Click Pending Changes >> Deploy Changes. 7. Click on the plus sign (+) under "Server Groups" and add a server group. Click "Submit". 8. Select the created server group and click the plus sign (+) in the Server Group <server group name> box. 9. Add the first configured authentication server. 10. Reselect the created server group and click the plus sign (+) in the Server Group <server group name> box. Click "Submit". 11. Expand "Admin Authentication Options" and select the created server group under "Server group:". 12. Click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- ARBA-ND-000340
- Vuln IDs
-
- V-266971
- Rule IDs
-
- SV-266971r1039934_rule
Checks: C-70895r1039932_chk
Review the site's backup policy to verify plans and procedures are in place to back up AOS configurations when changes occur. If the site does not have a policy to back up AOS configurations when changes occur, this is a finding.
Fix: F-70798r1039933_fix
Configure AOS with the following commands: 1. In the AOS CLI, create the backup file: backup config <filename> 2. Copy the file to a central server: copy flash: <filename> scp: <scp server IPv4 or IPv6 address> <username> <destination filename>
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- ARBA-ND-000341
- Vuln IDs
-
- V-266972
- Rule IDs
-
- SV-266972r1039937_rule
Checks: C-70896r1039935_chk
Review the site's backup policy to verify plans and procedures are in place to back up AOS configurations when changes occur or weekly, whichever is sooner. If the site does not have a policy to back up AOS configurations when changes occur or weekly, whichever is sooner, this is a finding.
Fix: F-70799r1039936_fix
Configure AOS with the following commands: 1. In the AOS CLI, create the backup file: backup config <filename> 2. Copy the file to a central server: copy flash: <filename> scp: <scp server IPv4 or IPv6 address> <username> <destination filename>
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- ARBA-ND-000344
- Vuln IDs
-
- V-266973
- Rule IDs
-
- SV-266973r1264025_rule
Checks: C-70897r1039938_chk
Interview the system administrator and determine if the network device obtains public key certificates from an appropriate certificate policy through an approved service provider. If the network device does not obtain its public key certificates from an appropriate certificate policy through an approved service provider, this is a finding.
Fix: F-70800r1264024_fix
Configure AOS with the following commands: crypto pki csr rsa key_len 2048 common_name <common_name> country <US> state_or_province <state> city <city> organization <org> unit <unit> email <email> show crypto pki csr 1. Use DoW PKI to generate a public certificate based on the CSR. 2. Using the web GUI, navigate to Configuration >> System >> Certificates > Import Certificates. 3. Click the plus sign (+) and enter "Certificate name:", browse to the public certificate file, choose the appropriate format, select Certificate type: "ServerCert", and click "Submit". 4. Click Pending Changes >> Deploy Changes. 5. Navigate to Configuration >> System >> Admin >> Admin Authentication Options and choose the imported certificate under "Server Certificate". 6. Click Submit >> Pending Changes >> Deploy Changes.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001358
- Version
- ARBA-ND-000346
- Vuln IDs
-
- V-266975
- Rule IDs
-
- SV-266975r1051115_rule
Checks: C-70899r1039944_chk
Verify the AOS configuration with the following command: show mgmt-user If any user other than "admin" is present, this is a finding.
Fix: F-70802r1039945_fix
Configure AOS with the following commands: configure terminal no mgmt-user <username> for any existing users other than "admin". write memory
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- ARBA-ND-000347
- Vuln IDs
-
- V-266976
- Rule IDs
-
- SV-266976r1039949_rule
Checks: C-70900r1039947_chk
1. Verify the AOS configuration with the following command: show ntp status If "Authentication" shows "disabled", this is a finding. 2. show running-config | include ntp If at least one trusted NTP authentication-key is not configured and at least one NTP server configured to use the key, this is a finding.
Fix: F-70803r1039948_fix
Configure AOS with the following commands: configure terminal ntp authentication-key (keyid #> sha1 <plaintext key> ntp trusted-key <keyid #> ntp server <first fqdn, ipv4, or ipv6 address> key <keyid #> ntp server <second fqdn, ipv4, or ipv6 address> key <keyid #> ntp authenticate write memory
- RMF Control
- AU-4
- Severity
- H
- CCI
- CCI-001851
- Version
- ARBA-ND-000350
- Vuln IDs
-
- V-266977
- Rule IDs
-
- SV-266977r1137890_rule
Checks: C-70901r1039950_chk
Verify the AOS configuration with the following command: show logging server If at least two central log servers are not configured, this is a finding.
Fix: F-70804r1039951_fix
Configure AOS with the following commands: For two or more central syslog servers: configure terminal logging <IPv4 or IPv6 address> write memory