Skip to content

The Cisco ISE must be configured to disable Wireless Setup for production systems.

An XCCDF Rule

Description

<VulnDiscussion>ISE Wireless Setup is beta software so is not authorized for use in DoD. Wireless Setup is disabled by default after fresh installation of Cisco ISE. If you upgrade ISE from a previous version, the Wireless Setup menu does not appear. Wireless Setup requires ports 9103 and 9104 to be open. To close those ports, use the CLI to disable Wireless Setup. You can enable Wireless Setup in the ISE CLI with the command application configure ise, picking the option to enable Wireless Setup.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-242641r960966_rule
Severity
High
References
Updated



Remediation - Manual Procedure

Use the application configure command in EXEC mode to disable wireless setup.

application configure disable Wi-Fi setup