Skip to content

HPE Aruba Networking AOS Wireless Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000343

    Group
  • The network element must authenticate all network-connected endpoint devices before establishing any connection.

    Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. For distributed architectures (e.g., service-oriented architectures), th...
    Rule Medium Severity
  • SRG-NET-000352

    Group
  • SRG-NET-000369

    Group
  • AOS, in conjunction with a remote device, must prevent the device from simultaneously establishing nonremote connections with the system and communicating via some other connection to resources in external networks.

    Split tunneling would in effect allow unauthorized external connections, making the system more vulnerable to attack and to exfiltration of organizational information. This requirement applies to ...
    Rule Medium Severity
  • SRG-NET-000070

    Group
  • SRG-NET-000512

    Group
  • The site must conduct continuous wireless Intrusion Detection System (IDS) scanning.

    DOD networks are at risk and DOD data could be compromised if wireless scanning is not conducted to identify unauthorized wireless local area network (WLAN) clients and access points connected to o...
    Rule Medium Severity
  • SRG-NET-000131

    Group
  • AOS, when configured as a WLAN bridge, must not be configured to have any feature enabled that calls home to the vendor.

    Call-home services will routinely send data such as configuration and diagnostic information to the vendor for routine or emergency analysis and troubleshooting. There is a risk that transmission...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules