Introduction to AOS-CX Security
This document details essential security guidelines and best practices for the AOS-CX network operating system. It is designed for IT administrators responsible for the installation, configuration, and management of Aruba switches. The guide focuses on enhancing the security posture of both the management and control planes, crucial for maintaining a stable and secure enterprise network infrastructure. By implementing the strategies outlined herein, organizations can significantly improve the integrity and availability of their critical data and network devices.
Key Security Objectives
The hardening objectives presented in this guide are based on IETF BCP 61, emphasizing three core security principles:
- Authentication: Verifying the identity of users, devices, or processes.
- Data Confidentiality: Protecting data from unauthorized disclosure.
- Data Integrity: Safeguarding data against unauthorized modifications, both intentional and accidental.
These principles guide the recommendations for securing network devices, ensuring that interactions are with trusted entities and that data remains protected and accessible only to authorized personnel.
Scope of the Guide
This guide covers a range of security measures, including:
- Securing the CX Management Plane: Factory defaults, physical security, user management, and access control.
- Hardening the Control Plane: Policies, protocol security, and access controls.
- Trusted Supply Chain considerations.
- Resources for accessing HPE Aruba Networking support, software updates, and documentation.
For the most current information on features and platform support, consult the HPE Feature Navigator.
About the Document
This document provides security guidelines and best practices for management features and protocols within the AOS-CX software. It includes sample configurations to illustrate these practices. For detailed information on configuration syntax and advanced features, refer to the official software manuals available through the HPE Aruba Networking Support Portal.