The CIS HPE Aruba Networking CX Switch Benchmark v1.0.1, Level 1 has 28 automated and manual items. They are mapped here by control number only: the numbers come from the public Tenable audit file for it, the wording is mine, and the benchmark's own text is not reproduced. Where a control can be read from a config, the config checker looks for it; the rest need eyes on the box.
CIS 1.1.1The config checker looks for thisA separate local user group for security staff, allowed to read logs and little else, so nobody needs an admin account to audit.
Check: show user-group
CIS 1.1.2Check this by handPasswords and shared secrets are typed at the masked prompt, never inline on the command line where history and the screen keep them.
user admin password
radius-server host 192.0.2.10 key
CIS 1.1.3The config checker looks for thisA password complexity policy: minimum length, a character from each class, and a history so old passwords do not come back.
Check: show password-complexity
password complexity
minimum-length 14
lowercase-count 1
uppercase-count 1
numeric-count 1
special-char-count 1
history-count 5
enable
exitCIS 1.1.4The config checker looks for thisThe export password is your own, not the factory default, so secrets exported from this switch do not decrypt on any other CX switch.
Check: show running-config
service export-password
CIS 1.1.6Check this by handThe built-in admin account has a strong password.
user admin password
CIS 1.1.7Check this by handWhere the built-in groups do not fit, custom user groups allow only the commands listed in them.
Check: show user-group
CIS 1.1.8The config checker looks for thisCLI sessions are limited per user, close after 15 minutes idle, and login history is kept.
Check: show running-config | begin cli-session
cli-session
timeout 15
exitCIS 1.1.9The config checker looks for thisTelnet stays off on every VRF, which is the default. Remote CLI is SSH only.
Check: show telnet server
no telnet server vrf default
CIS 1.2.2The config checker looks for thisThe SSH allow-list is on, so only the management hosts or subnets listed can even try to log in.
Check: show ssh server
ssh server allow-list
ip 192.0.2.0/24
enable
exitCIS 1.2.4The config checker looks for thisSSH ciphers, MACs and key exchange are pinned to the list your policy approves instead of the defaults.
Check: show ssh server
ssh ciphers [email protected] [email protected] aes256-ctr aes128-ctr
ssh macs [email protected] [email protected] hmac-sha2-512 hmac-sha2-256
CIS 1.2.6Check this by handThe SSH host key is regenerated with a strong type: ECDSA nistp256, ed25519, or RSA of 2048 bits.
Check: show ssh host-key
ssh host-key ecdsa ecdsa-sha2-nistp256
CIS 1.3.1The config checker looks for thisNTP is authenticated with a shared key, so the switch only believes time servers that hold it.
Check: show ntp associations
ntp authentication
ntp authentication-key 1 sha1 <NTP-KEY>
ntp trusted-key 1
ntp server 192.0.2.30 key-id 1 iburst
CIS 1.3.2The config checker looks for thisThe clock and time zone are set and NTP runs against more than one server.
Check: show ntp status · show clock
clock timezone us/eastern
ntp server 192.0.2.30 iburst
ntp server 192.0.2.31 iburst
ntp enable
CIS 1.4.1.1The config checker looks for thisNo SNMP community is public or private, communities are read-only unless write is needed, and an access list limits who may ask.
Check: show snmp community
no snmp-server community public
CIS 1.5.3.1The config checker looks for thisThe switch's own role-based rules decide which commands each user may run.
Check: show aaa authorization
aaa authorization commands ssh group local
aaa authorization commands console group local
CIS 1.5.4.1The config checker looks for thisAccounting is also kept on the switch, so the record of who did what survives the AAA server being down.
Check: show aaa accounting
aaa accounting all-mgmt default start-stop local
CIS 1.7.1Check this by handOnly HPE-signed firmware loads. The switch checks the signature at download and at every boot.
Check: show version
CIS 1.8.1.1The config checker looks for thisFiles move to and from the switch with SCP or SFTP, never TFTP.
Check: show running-config | include tftp
CIS 1.9.1The config checker looks for thisThe web UI and REST API are only on in the VRFs someone manages the switch from.
Check: show https-server
no https-server vrf default
CIS 1.9.2The config checker looks for thisWeb sessions time out as soon as operations allow; five minutes when only people use the web UI.
Check: show https-server
https-server session-timeout 5
CIS 1.10.1The config checker looks for thisServiceOS asks for a password at the console. Out of the box anyone at the console gets in as admin with none.
Check: show running-config | include serviceos
system serviceos password-prompt
CIS 1.12The config checker looks for thisA banner before login says the switch is for authorized use only.
Check: show banner motd
banner motd ^
Authorized use only. Activity on this switch is logged.
^
CIS 1.13The config checker looks for thisA scheduled job copies the running config off the switch regularly, over SFTP or SCP.
Check: show job · show schedule
CIS 1.14The config checker looks for thisThe hostname is unique and says where the switch is.
Check: show system
hostname idf2-sw1
CIS 2.1.2Check this by handFactory reset from the front panel button stays off, which is the default, so physical access is not a wipe.
CIS 2.1.3The config checker looks for thisEvery port nothing is plugged into is shut down.
Check: show interface brief
interface 1/1/20-1/1/24
shutdown
exitCIS 4.2.1The config checker looks for thisAccess ports facing end devices run BPDU guard: a switch plugged in shuts the port.
Check: show spanning-tree
interface 1/1/1-1/1/20
spanning-tree bpdu-guard
exitCIS 4.2.2The config checker looks for thisPorts that should never lead toward the root bridge run root guard.
Check: show spanning-tree
interface 1/1/1-1/1/20
spanning-tree root-guard
exit