CX Sandbox

Releases, habits and hardening

What changed from AOS-CX 10.15 to 10.18 for the 6200 and 6300, seen three ways: HPE's Feature Navigator, the command lists I pulled off the Switch Simulator for each release, and the sandbox's own notes. Then the habits that keep a campus access switch out of trouble, and hardening mapped to the CIS benchmark for CX switches by control number. Every config line on this page is checked against the command set before it is published.

By release

Newest first. The Feature Navigator is HPE's list of what each platform supports in each release, compared here with licenses Native and Advanced and read on 2026-09-28; a feature sits under the first release it shows up in. The command line column is the difference between the command lists of one release and the one before it, which catches syntax the navigator never mentions. The Simulator hides hardware, so PoE, VSF and some speeds do not show there.

AOS-CX 10.18

In HPE's Feature Navigator

Not in the Feature Navigator yet (checked 2026-09-28). The command line below is the first place 10.18 shows.

In the command line

482 command forms appear in 10.18 and 15 that 10.17 had are gone, across the contexts the lists cover. Forms, not features: one new option can add a few.

config 29 new command forms
  • nae-agent WORD WORD false ciphertext LINE and 11 more like it
  • ip source-interface mist A.B.C.D {vrf} and 1 more like it
  • ipv6 source-interface mist X:X::X:X {vrf} and 1 more like it
  • debug cxpm all {severity}
  • debug nginxconfigurator mist {severity}
  • ip dns fqdn-resolver response-timeout <n>
  • maintenance-mode activate {profile}
  • maintenance-mode profile WORD
  • maintenance-unit bgp WORD
  • maintenance-unit ospfv2 WORD
  • maintenance-unit ospfv3 WORD
  • maintenance-unit ospfv3-af-ipv4 WORD
  • maintenance-unit ospfv3-af-ipv6 WORD
  • mgmd vsx-peer-report-sync
  • mist
  • troubleshoot proactive
interface 9 new command forms
  • ip igmp snooping fastleave auto-vlans and 1 more like it
  • ipv6 mld snooping fastleave auto-vlans and 1 more like it
  • aaa authentication port-access client-limit device-mode <n>
  • ip ospf network point-to-multipoint {dynamic}
  • ipv6 ospfv3 neighbor X:X::X:X
  • ipv6 ospfv3 network point-to-multipoint {dynamic}
  • lldp med force-send
LAG 3 new command forms
  • ip ospf network point-to-multipoint {dynamic}
  • ipv6 ospfv3 neighbor X:X::X:X
  • ipv6 ospfv3 network point-to-multipoint {dynamic}
VLAN 4 new command forms
  • ip igmp snooping report-suppression disable and 1 more like it
  • ipv6 mld snooping report-suppression disable and 1 more like it
VLAN interface 3 new command forms
  • ip ospf network point-to-multipoint {dynamic}
  • ipv6 ospfv3 neighbor X:X::X:X
  • ipv6 ospfv3 network point-to-multipoint {dynamic}
port-access role 46 new command forms
  • speed auto 100g and 9 more like it
  • rate-limits broadcast WORD kbps and 2 more like it
  • rate-limits icmp WORD kbps and 2 more like it
  • rate-limits icmp-version ip-all and 2 more like it
  • rate-limits multicast WORD kbps and 2 more like it
  • rate-limits unknown-unicast WORD kbps and 2 more like it
  • client-limit device-mode <n>
  • rpvst-enable
  • speed 10-full
  • speed 10-half
  • speed 100-full
  • speed 100-half
  • speed 1000-full
  • speed 100g
  • speed 10g
  • speed 200g
  • speed 25g
  • speed 400g
  • speed 40g
  • speed 50g
  • stp-bpdu-filter
  • stp-bpdu-guard
  • stp-link-type point-to-point
  • stp-link-type shared
  • stp-root-guard
  • toggle-link
  • voice-vlan <n>
LLDP group 4 new command forms
  • seq <n> ignore {chassis-id|sys-desc|sysname|vendor-oui} and 1 more like it
  • ignore {chassis-id|sys-desc|sysname|vendor-oui}
  • match {chassis-id|sys-desc|sysname|vendor-oui}
RADIUS group 2 new command forms
  • load-balancing-mode priority-based
  • load-balancing-mode round-robin
OSPF 6 new command forms
  • max-metric router-lsa external-lsa and 5 more like it
exec 376 new command forms
  • troubleshoot l3 arp and 72 more like it
  • troubleshoot aaa-mgmt and 37 more like it
  • troubleshoot multicast config and 37 more like it
  • troubleshoot classifier and 23 more like it
  • troubleshoot platform and 23 more like it
  • troubleshoot system and 15 more like it
  • troubleshoot l2 and 14 more like it
  • show ip multicast bridging datapath group A.B.C.D source A.B.C.D {vsx-peer} and 12 more like it
  • troubleshoot tunnel and 12 more like it
  • troubleshoot port-access and 11 more like it
  • show ipv6 multicast bridging datapath group X:X::X:X source X:X::X:X {vsx-peer} and 9 more like it
  • troubleshoot client-insight and 9 more like it
  • troubleshoot feature-pack and 8 more like it
  • troubleshoot copp and 6 more like it
  • troubleshoot bluetooth and 5 more like it
  • troubleshoot mirror and 5 more like it
  • troubleshoot radius and 5 more like it
  • troubleshoot usb and 5 more like it
  • copy checkpoint WORD WORD checkpoint {vrf} and 2 more like it
  • copy support-files top-cpu WORD and 2 more like it
  • clear mac-address mac-move rapid vlan <n> and 1 more like it
  • show aaa server-groups radius WORD {vsx-peer} and 1 more like it
  • show interface IFNAME dom {detail} {formatted|vsx-peer} and 1 more like it
  • show ip igmp interface IFNAME fastleave {vsx-peer} and 1 more like it
  • show ip source-interface mist all-vrfs {vsx-peer} and 1 more like it
  • show ipv6 mld interface IFNAME fastleave {vsx-peer} and 1 more like it
  • show ipv6 source-interface mist all-vrfs {vsx-peer} and 1 more like it
  • show mac-address-table mac-move rapid vlan <n> {format|vsx-peer} and 1 more like it
  • show system resource-utilization daemon WORD detail {vsx-peer} and 1 more like it
  • checkpoint auto confirm {skip-checkpoint}
  • clear mist registration-info
  • clear screen
  • debug cxpm all {severity}
  • debug nginxconfigurator mist {severity}
  • mist registration-code WORD
  • show interface dom {detail} {formatted|vsx-peer}
  • show interface transceiver capabilities {vsx-peer}
  • show interface vxlan vteps status count
  • show ip dns fqdn-resolver response-timeout {vsx-peer}
  • show lldp neighbor-info json {vsx-peer}
config 4 gone command forms
  • aaa authentication port-access cached-critical-role persistent-storage and 2 more like it
  • debug flowtelemetry all {severity}
interface 1 gone command form
  • ip ospf network point-to-multipoint
LAG 1 gone command form
  • ip ospf network point-to-multipoint
VLAN interface 1 gone command form
  • ip ospf network point-to-multipoint
LLDP group 4 gone command forms
  • seq <n> ignore {sys-desc|sysname|vendor-oui} and 1 more like it
  • ignore {sys-desc|sysname|vendor-oui}
  • match {sys-desc|sysname|vendor-oui}
exec 4 gone command forms
  • checkpoint auto confirm
  • debug flowtelemetry all {severity}
  • show interface IFNAME dom {detail|vsx-peer}
  • show interface dom {detail|vsx-peer}

Called out in the command notes

AOS-CX 10.17

In HPE's Feature Navigator

48 features first listed for the 6200 or 6300 in 10.17.0001.

ACL

  • VSF Member ACL Logging Support with Full Details 6200 6300

BGP

  • BGP route selection option within BGP RIB 6300
  • Optimized Inter Subnet Multicast Support for VXLAN (OISM) 6300

CX Edge Insights

  • Display and report CPS excursions per ARC client 6200 6300
  • Reporting flow congestion probability 6200 6300

L2 features

  • Persona Support on Lag interfaces 6200 6300

L3 features

  • Active-Active DHCP-Relay support on VSX based with CLI 6300
  • DHCPv4 Relay option82 Remote-Id support with CLI 6200 6300
  • Selective Exemption of specific IP address from ARP/ND suppression 6300
  • Selective Exemption of specific IP address from LPA 6200 6300

L3 features: tunnels

  • 6in4 tunnel support with sub-interface in the underlay 6300
  • 6in6 tunnel support with sub-interface in the underlay 6300
  • GRE tunnel support with sub-interface in the underlay 6300

Management

  • Apply non-failsafe updates during boot 6200 6300
  • Local Packet capture with filters 6300
  • Support for DHCP on all VLANS 6200 6300
  • Using DOT & _ (underscore) in CX hostname 6200 6300

Management: Security

  • Disable Local Admin Account 6200 6300

Multicast

  • IGMP control packet forwarding in HW 6300
  • Multicast: BudNode Support for Underlay EVPN VXLAN 6300
  • Multicast: IVRL Dynamic RP Support 6300
  • Multicast: IVRL Group based filtering 6300
  • Multicast: IVRL Increase Scale (Sources and VRFs) 6300
  • Multicast: OISM Optimized Inter Subnet Multicast support for VXLAN 6300
  • Multicast: SM support in underlay for EVPN VXLAN 6300
  • PIM BiDir IPv6 Support 6300

Port

  • Front panel port mapping with ASIC ports 6200 6300

Port Access Security

  • Auto Generation of Probe File for Silent Client Authentication 6300
  • FQDN Support for Port Access Policy: LUR/DUR/Aruba-NAS-Filter-Rule 6200 6300
  • sticky mac clear command 6200 6300

QoS

  • Queue Congestion History 6200 6300

Supportability

  • CX Assistant support for system troubleshooting 6200 6300
  • Enable prompt to save config when logging out 6200 6300
  • Event trap disable CLI 6200 6300

Telemetry

  • gNMI: Enable secure connectivity via HTTP2 gNMI gRPC APIs 6300
  • gNMI: OpenConfig Interfaces YANG models 6300
  • gNMI: OpenConfig Platform YANG models 6300
  • gNMI: OpenConfig System YANG models 6300
  • gNMI: Subscribe and Capabilities methods 6300
  • IP Flow Path Trace 6200 6300
  • IPFIX: drop exception/mirror on drop 6200
  • Support for IPFIX configuration on out interface using IP Flow table 6200 6300

Timing Protocol

  • NTP Client/Conductor Authentication: AES128 Support 6200 6300
  • PTP Boundary Clock Support with VSF Stack 6300
  • PTP Multi-VLAN support 6300
  • PTP Transparent Clock on VSF (Peer to Peer Delay mechanism only) 6300

VXLAN

  • Per VLAN ARP/ND suppression 6300
  • VXLAN Tunnel support with sub-interface in the underlay 6300

In the command line

158 command forms appear in 10.17 and 55 that 10.16 had are gone, across the contexts the lists cover. Forms, not features: one new option can add a few.

config 47 new command forms
  • ip route A.B.C.D WORD A.B.C.D {bfd|distance|name|tag|track|use-forwarding-address|...} and 4 more like it
  • ip route A.B.C.D/M A.B.C.D {bfd|distance|name|tag|track|use-forwarding-address|...} and 4 more like it
  • ipv6 route X:X::X:X IFNAME {distance|name|tag|track|vrf} and 3 more like it
  • aaa authentication login gnmi group LINE and 2 more like it
  • ntp authentication-key <n> aes128 and 2 more like it
  • aaa accounting all-mgmt gnmi start-stop group LINE and 1 more like it
  • user WORD disable and 1 more like it
  • crypto pki application gnmi certificate WORD
  • debug classifier taskd {severity}
  • debug dnld apps {severity}
  • debug dnld mgmt {severity}
  • debug dnld ui {severity}
  • debug fqdnresolver all {severity}
  • debug fwupd all {severity}
  • debug nginxconfigurator all {severity}
  • debug nginxconfigurator gnmi {severity}
  • debug saint all {severity}
  • debug saint msg {severity}
  • debug statsmon all {severity}
  • debug statsmon mgmt {severity}
  • dhcp-relay option 82 circuit-id port-id
  • dhcp-relay vsx active-active
  • early-access
  • event-trap-disable LINE
  • gnmi vrf WORD
  • interface persona lag WORD
  • ip dns fqdn-resolver refresh-interval <n>
  • port-access secure-update gbp
  • port-access secure-update policy
  • static-mac WORD {vlan} port IFNAME
interface 14 new command forms
  • aaa authentication port-access lldp-loop-guard enable
  • ip ospf network point-to-multipoint
  • ip pim-bidir hello-holdtime <n>
  • ip pim-dense hello-holdtime <n>
  • ip pim-sparse hello-holdtime <n>
  • ipv6 pim6-bidir disable
  • ipv6 pim6-bidir enable
  • ipv6 pim6-bidir hello-holdtime <n>
  • ipv6 pim6-bidir hello-interval <n>
  • ipv6 pim6-bidir lan-prune-delay
  • ipv6 pim6-bidir override-interval <n>
  • ipv6 pim6-bidir propagation-delay <n>
  • ipv6 pim6-dense hello-holdtime <n>
  • ipv6 pim6-sparse hello-holdtime <n>
LAG 15 new command forms
  • persona custom WORD attach and 1 more like it
  • ip ospf network point-to-multipoint
  • ip pim-bidir hello-holdtime <n>
  • ip pim-dense hello-holdtime <n>
  • ip pim-sparse hello-holdtime <n>
  • ipv6 pim6-bidir disable
  • ipv6 pim6-bidir enable
  • ipv6 pim6-bidir hello-holdtime <n>
  • ipv6 pim6-bidir hello-interval <n>
  • ipv6 pim6-bidir lan-prune-delay
  • ipv6 pim6-bidir override-interval <n>
  • ipv6 pim6-bidir propagation-delay <n>
  • ipv6 pim6-dense hello-holdtime <n>
  • ipv6 pim6-sparse hello-holdtime <n>
VLAN interface 15 new command forms
  • ip ospf network point-to-multipoint
  • ip pim-bidir hello-holdtime <n>
  • ip pim-dense hello-holdtime <n>
  • ip pim-sparse accept-remote-source
  • ip pim-sparse hello-holdtime <n>
  • ipv6 pim6-bidir disable
  • ipv6 pim6-bidir enable
  • ipv6 pim6-bidir hello-holdtime <n>
  • ipv6 pim6-bidir hello-interval <n>
  • ipv6 pim6-bidir lan-prune-delay
  • ipv6 pim6-bidir override-interval <n>
  • ipv6 pim6-bidir propagation-delay <n>
  • ipv6 pim6-dense hello-holdtime <n>
  • ipv6 pim6-sparse accept-remote-source
  • ipv6 pim6-sparse hello-holdtime <n>
OSPF 1 new command form
  • neighbor A.B.C.D
exec 66 new command forms
  • show mac-address-table dynamic interface WORD {format|vsx-peer} and 4 more like it
  • show interface vxlan vni and 3 more like it
  • show ipv6 pim6 dfe all-vrfs {vsx-peer} and 3 more like it
  • show ip dns fqdn-resolver detail {fqdn|requested-address-family|source|vrf|vsx-peer} and 2 more like it
  • show mac-address-table interface WORD detail {format|vsx-peer} and 2 more like it
  • show port-access role clearpass {vsx-peer} and 2 more like it
  • vsx update-software WORD {vrf} {allow-non-failsafe-updates} and 2 more like it
  • clear mac-address WORD vlan <n> {force} and 1 more like it
  • port-access log-off client onboarded-method port-security dynamic and 1 more like it
  • show interface hardware-port <n> {vsx-peer} and 1 more like it
  • show mac-address-table mac-move vlan <n> {format|vsx-peer} and 1 more like it
  • container WORD pause
  • debug classifier taskd {severity}
  • debug dnld apps {severity}
  • debug dnld mgmt {severity}
  • debug dnld ui {severity}
  • debug fqdnresolver all {severity}
  • debug fwupd all {severity}
  • debug nginxconfigurator all {severity}
  • debug nginxconfigurator gnmi {severity}
  • debug saint all {severity}
  • debug saint msg {severity}
  • debug statsmon all {severity}
  • debug statsmon mgmt {severity}
  • ip dns fqdn-resolver force-refresh {fqdn|source|status|vrf}
  • logout
  • rename ssh sftp-server WORD WORD
  • show capacities logging {vsx-peer}
  • show capacities-status logging {vsx-peer}
  • show gnmi {vsx-peer}
  • show interface IFNAME hardware-port {vsx-peer}
  • show mac-address-table address WORD {format|vsx-peer}
  • show mac-address-table detail {format|vsx-peer}
  • show mac-address-table hsc {format|vsx-peer}
  • show mac-address-table lockout {format|vsx-peer}
  • show mac-address-table port WORD {format|vsx-peer}
  • show mac-address-table static {format|vsx-peer}
  • show mac-address-table unsorted {format|vsx-peer}
  • show mac-address-table vlan <n> {format|vsx-peer}
  • show mac-address-table {format|vsx-peer}
config 23 gone command forms
  • ip route A.B.C.D WORD A.B.C.D {bfd|distance|tag|track|use-forwarding-address|vrf} and 4 more like it
  • ip route A.B.C.D/M A.B.C.D {bfd|distance|tag|track|use-forwarding-address|vrf} and 4 more like it
  • ipv6 route X:X::X:X IFNAME {distance|tag|track|vrf} and 3 more like it
  • troubleshoot l3 and 2 more like it
  • troubleshoot multicast and 2 more like it
  • troubleshoot app-recognition and 1 more like it
  • static-mac aa:bb:cc:dd:ee:ff {vlan} port IFNAME
exec 32 gone command forms
  • show mac-address-table dynamic interface WORD {vsx-peer} and 4 more like it
  • show mac-address-table interface WORD detail {vsx-peer} and 2 more like it
  • show port-access role clearpass and 2 more like it
  • vsx update-software WORD {vrf} and 2 more like it
  • clear mac-address aa:bb:cc:dd:ee:ff vlan <n> {force} and 1 more like it
  • show interface vxlan vni <n> {vteps} and 1 more like it
  • show mac-address-table mac-move vlan <n> {vsx-peer} and 1 more like it
  • troubleshoot app-recognition and 1 more like it
  • show mac-address-table address a:b:c:d:e:f {vsx-peer}
  • show mac-address-table detail {vsx-peer}
  • show mac-address-table hsc {vsx-peer}
  • show mac-address-table lockout {vsx-peer}
  • show mac-address-table port WORD {vsx-peer}
  • show mac-address-table static {vsx-peer}
  • show mac-address-table unsorted {vsx-peer}
  • show mac-address-table vlan <n> {vsx-peer}
  • show mac-address-table {vsx-peer}
  • show vsx mac-address-table mac a:b:c:d:e:f vlan <n> {vsx-peer}

Called out in the command notes

AOS-CX 10.16

In HPE's Feature Navigator

76 features first listed for the 6200 or 6300 in 10.16.1006.

BGP

  • eBGP Unnumbered neighbor 6300
  • EVPN route-type 6 support (Tenant Routed Multicast) 6300
  • Route Target Rewrite across Fabrics 6300

CX Edge Insights

  • Application Based Policy (ABP): DSCP/Local Priority Remark and Mirror Actions 6200
  • Application Based Policy (ABP): Permit/Deny Traffic 6200
  • Application Recognition 6200
  • Application Recognition: enablement 6200
  • Application Recognition: max number of active flows 6200
  • Application Recognition: Measure Application Experience 6200
  • Application Recognition: Mode 6200
  • Application Recognition: number of recognized applications 6200

Container

  • Support for Docker Infrastructure 6300

L3 features

  • ARP Latency and failures to gateway 6200 6300
  • Local Proxy ARP 6200

Management

  • Hibernation mode 6300
  • IPSLA Customized Average Interval 6200 6300
  • IPv6 only Preferred option for DHCPv4 6200 6300
  • PSU Input voltage monitoring 6200 6300
  • Route/resource tracking using IP SLA (Static Routes, without NAE) 6200 6300
  • Support for "Reload at" and "Reload after" 6200 6300
  • Support for Deep mode in Checkpoint Diff command 6200 6300
  • XCVR MIB for Power/DOM details 6200 6300

Management: security

  • TLS 1.3 Support 6200 6300

Multicast

  • IGMP/MLD Snooping Global Enable 6200 6300

Port Access Security

  • Enable the AAA authentication command under interface persona 6200 6300
  • IPV6 Support for UBT Tunnels 6200 6300
  • RADIUS Proxy Support for Role Based Policy Enforcement 6300
  • Silent Client Probe 6200 6300

Supportability

  • Copy Support-files to Central 6200 6300

Telemetry

  • IPFIX: additional attributes export (local-priority, VRF, DSCP, interface details) 6200
  • IPFIX: drop exception/mirror on drop 6300
  • Traffic-Insight: Blocked Flow Visibility: Policy/Forwarding Details 6200 6300

Timing Protocol

  • PTP profile 1588v2 6200

VSX

  • active-forwarding 6300
  • active-forwarding SVI 6300
  • active-gateway and DHCP relay 6300
  • active-gateway and DHCP server 6300
  • Configuration Synchronization (vsx-sync) 6300
  • Dual-DR / proxy-DR 6300
  • IGMP snooping 6300
  • IGMP support 6300
  • IGMP/MLD graceful-shutdown during upgrade 6300
  • IGMP/MLD groups supported for Dual-DR (active/active) 6300
  • IPv4 multicast routes for Dual-DR (active/active) 6300
  • IPv6 multicast routes for Dual-DR (active/active) 6300
  • LACP fallback: L2 control plane synchronization 6300
  • LACP fallback: VSX LAG 6300
  • LACP graceful-shutdown during upgrade 6300
  • local first forwarding 6300
  • max number of VSX LAGs 6300
  • MLD 6300
  • MLD snooping 6300
  • nodes in VSX cluster 6300
  • number of interfaces per VSX LAG per VSX cluster 6300
  • number of interfaces per VSX LAG per VSX node 6300
  • OSPF/BGP/VRRP graceful-shutdown during upgrade 6300
  • PIM BIDIR 6300
  • PIM graceful-shutdown during upgrade 6300
  • PIM SM 6300
  • PIM-SSM 6300
  • recommended max number of VSX LAGs 6300
  • static VSX LAG 6300
  • sub-second VSX Live upgrade for multicast 6300
  • sub-second VSX Live upgrade for unicast 6300
  • VRRP support 6300
  • VSX and MSTP 6300
  • VSX and RPVST+ 6300
  • VSX keepalive IPv6 support 6300
  • VSX keepalive over OOBM 6300
  • VSX LAG ( MCLAG name in VSX technology) 6300
  • VSX Live upgrade: API 6300
  • VSX Live upgrade: CLI command 6300
  • VSX shut-on-split 6300
  • vsx-configmate 6300
  • VSX-VRRP Active-Active on Data Plane 6300

ZTP / OTP

  • ZTP using USB 6200 6300

In the command line

258 command forms appear in 10.16 and 56 that 10.15 had are gone, across the contexts the lists cover. Forms, not features: one new option can add a few.

config 29 new command forms
  • ip route A.B.C.D WORD A.B.C.D {bfd|distance|tag|track|use-forwarding-address|vrf} and 2 more like it
  • ip route A.B.C.D/M A.B.C.D {bfd|distance|tag|track|use-forwarding-address|vrf} and 2 more like it
  • track-object WORD ip-sla WORD and 2 more like it
  • troubleshoot l3 and 2 more like it
  • troubleshoot multicast and 2 more like it
  • ipv6 route X:X::X:X IFNAME {distance|tag|track|vrf} and 1 more like it
  • troubleshoot app-recognition and 1 more like it
  • debug schedule all {severity}
  • debug schedule reload {severity}
  • https-server rest swagger
  • ip arp ignore-subnet-match {vrf}
  • ip igmp snooping all-vlans
  • ipv6 mld snooping all-vlans
  • multicast flow-activity-poll-timer <n>
  • ntp max-distance <n>
  • sflow reachability-check
  • tls global
LLDP group 20 new command forms
  • seq <n> ignore sys-desc WORD vendor-oui WORD type <n> {value} sysname WORD and 9 more like it
  • ignore vendor-oui WORD type <n> {value} sys-desc WORD {sysname} and 1 more like it
  • match vendor-oui WORD type <n> {value} sys-desc WORD {sysname} and 1 more like it
  • ignore sys-desc WORD vendor-oui WORD type <n> {value} sysname WORD
  • ignore sysname WORD vendor-oui WORD type <n> {value} sys-desc WORD
  • ignore {sys-desc|sysname} vendor-oui WORD type <n> {value}
  • match sys-desc WORD vendor-oui WORD type <n> {value} sysname WORD
  • match sysname WORD vendor-oui WORD type <n> {value} sys-desc WORD
  • match {sys-desc|sysname} vendor-oui WORD type <n> {value}
UBT zone 2 new command forms
  • backup-controller ip X:X::X:X
  • primary-controller ip X:X::X:X
RADIUS group 2 new command forms
  • server WORD tls {port|priority|vrf} and 1 more like it
exec 205 new command forms
  • show bgp l2vpn evpn WORD : : : mcastgrpip : origip {vsx-peer} and 34 more like it
  • clear access-list hitcounts interface lag <n> and 20 more like it
  • show access-list hitcounts interface lag <n> in {vsx-peer} and 20 more like it
  • show access-list interface lag <n> in {commands|configuration|vsx-peer} and 20 more like it
  • checkpoint diff WORD WORD {deep} and 17 more like it
  • clear bgp IFNAME and 17 more like it
  • show bgp vrf WORD ipv4 unicast neighbors IFNAME advertised-routes {vsx-peer} and 11 more like it
  • show port-access clients vlan-info mac MAC and 6 more like it
  • show bgp all neighbors IFNAME advertised-routes {vsx-peer} and 5 more like it
  • show bgp ipv4 unicast neighbors IFNAME advertised-routes {vsx-peer} and 5 more like it
  • show bgp ipv6 unicast neighbors IFNAME advertised-routes {vsx-peer} and 5 more like it
  • troubleshoot l3 and 2 more like it
  • troubleshoot multicast and 2 more like it
  • show aaa authentication port-access dot1x supplicant status detail interface vlan <n> and 1 more like it
  • show ipv6 neighbors evpn vrf WORD X:X::X:X {vsx-peer} and 1 more like it
  • troubleshoot app-recognition and 1 more like it
  • debug schedule all {severity}
  • debug schedule reload {severity}
  • reload after dd:hh:mm
  • reload at WORD hh:mm:ss
  • reload cancel
  • show arp evpn vrf WORD ip A.B.C.D {vsx-peer}
  • show arp vrf WORD ip A.B.C.D {vsx-peer}
  • show https-server rest swagger {vsx-peer}
  • show interface IFNAME flow-control {detail|vsx-peer}
  • show interface flow-control {detail|vsx-peer}
  • show ip-sla WORD history-results
  • show reload
  • show reload status
  • show running-config tls global
  • show running-config track-object
  • show running-config track-object-list
  • show tls global {vsx-peer}
  • show track-object WORD
  • show track-object all
  • show troubleshoot details instance <n>
  • show troubleshoot history
  • usb format expanded-storage
config 15 gone command forms
  • led locator fast_blink and 4 more like it
  • ip route A.B.C.D WORD A.B.C.D {bfd|distance|tag|use-forwarding-address|vrf} and 2 more like it
  • ip route A.B.C.D/M A.B.C.D {bfd|distance|tag|use-forwarding-address|vrf} and 2 more like it
  • ipv6 route X:X::X:X IFNAME {distance|tag|vrf} and 1 more like it
  • mgmd client-details and 1 more like it
LLDP group 4 gone command forms
  • seq <n> ignore {vendor-oui} and 1 more like it
  • ignore {vendor-oui}
  • match {vendor-oui}
RADIUS group 2 gone command forms
  • server WORD tls {port|vrf} and 1 more like it
exec 35 gone command forms
  • checkpoint diff WORD WORD and 13 more like it
  • show ip igmp snooping vlan <n> group A.B.C.D client_details verbose {vsx-peer} and 7 more like it
  • show ipv6 mld snooping vlan <n> group X:X::X:X client_details verbose {vsx-peer} and 7 more like it
  • show interface IFNAME flow-control detail {vsx-peer} and 1 more like it
  • show interface flow-control detail {vsx-peer} and 1 more like it
  • multicast flow-activity-poll-timer <n>

Called out in the command notes

AOS-CX 10.15

In HPE's Feature Navigator

32 features first listed for the 6200 or 6300 in 10.15.0005 and 10.15.1005.

BGP

  • Clear BGP soft out 6300

CX Edge Insights

  • Application Recognition: Measure Application Experience 6300

L3 features: security

  • DHCP Snooping logs reporting Rogue Server IP and Ports 6200 6300

L3 features: tunnels

  • BGP over GRE IPv4 tunnels with IVRL 6300

Management

  • IPSLA: IPv6 Support 6200 6300
  • IPv6 DHCP client 6200 6300
  • NAE Lite: Support for Date/Time & Hostname in Redirection 6200 6300
  • NAE Lite: Support for SFTP/SCP Transfer 6200 6300
  • SFTP server support for external firmware push 6200 6300
  • Support for “Overwrite” option in Copy Remote to Running Config 6200 6300

Management: security

  • AAA Troubleshoot Test-Server 6200 6300
  • Privelege-Elevation for Administrators user group 6200 6300
  • Subject Alternative Name Extensions in CSR 6200 6300

Multicast

  • Muticast inter VRF route leaking 6300

OSPFv3

  • address-family support 6200 6300

Supportability

  • Process Monitor & Statistics 6200 6300
  • show forwarding-info (egress path tracing for VXLAN) 6300
  • show forwarding-info (L2 and L3 egress path tracing for LAG and ECMP) 6200 6300

Telemetry

  • Client-Insight: L2 and L3 On-going details per client 6200 6300
  • IPFIX: additional attributes export (local-priority, VRF, DSCP, interface details) 6300

Timing Protocol

  • PTP 6200
  • PTP clock-step 6200
  • PTP Forward PTPv1 packets 6200
  • PTP lag-role 6200
  • PTP profile AES-67 6200
  • PTP profile AES-R16 6200
  • PTP profile SMPTE 6200
  • PTP transparent clock 6200
  • PTP transparent clock mode 6200
  • PTP transport protocol 6200

VSF

  • Disable Egress shaping for VSF ports 6300

ZTP / OTP

  • ZTP IPV6 Support (Over OOBM Only) 6200 6300

In the command line

The baseline: 13972 command forms across the contexts harvested. Every later release is compared with the one before it.

Called out in the command notes

Best practices for a campus access switch

The habits, each with the few lines that do it. The script builder writes most of them for you, and the config checker tells you which a config is missing.

Name everything

Hostname with the location in it, a name on every VLAN, a description on every uplink and anything odd. At 2 a.m. the next person reads show interface brief and LLDP, not your ticket.

hostname idf2-sw1
vlan 10
    name STAFF
    exit
interface lag 1
    description uplink to core
    exit
The note on hostname <WORD>

Spanning tree on, and the root chosen

MSTP on every switch. The root is the core, set on purpose with a low priority there; an access switch keeps the default so it never wins by accident.

spanning-tree
The note on spanning-tree

Edge ports protect themselves

admin-edge so a laptop gets its address without waiting, BPDU guard so a switch plugged into a desk shuts the port, loop-protect for the loop through an unmanaged switch that swallows BPDUs.

interface 1/1/1-1/1/20
    spanning-tree port-type admin-edge
    spanning-tree bpdu-guard
    loop-protect
    exit
The note on spanning-tree bpdu-guard

Uplinks are LACP LAGs

Two links in a LAG, LACP active on both ends so each checks the other, rate fast so a dead member is noticed in seconds. On 10.18 the LAG starts shut: no shutdown it.

interface lag 1
    no shutdown
    lacp mode active
    lacp rate fast
    exit
interface 1/1/27-1/1/28
    lag 1
    exit
The note on interface lag <1-256>

Trunks carry what they need

An explicit allowed list, never all, and the native VLAN picked on purpose. VLAN 1 as native is how untagged frames end up somewhere nobody meant.

interface lag 1
    vlan trunk native 99
    vlan trunk allowed 10,30,99
    exit
The note on vlan trunk allowed <VLIST>

Two RADIUS servers in one group

Port access points at a group. With one server in it, a ClearPass reboot is an outage for every desk.

radius-server host 192.0.2.10 key plaintext <SHARED-SECRET>
radius-server host 192.0.2.11 key plaintext <SHARED-SECRET>
aaa group server radius CLEARPASS
    server 192.0.2.10
    server 192.0.2.11
    exit
The note on aaa group server radius <WORD>

Decide what happens when ClearPass is down

A critical role on every port-access port. Whether that means business as usual or a quarantine VLAN is a decision to make before the outage, not during it.

interface 1/1/1-1/1/20
    aaa authentication port-access critical-role CRITICAL
    exit
The note on aaa authentication port-access critical-role <WORD>

Let ClearPass change its mind

CoA lets ClearPass re-role or kick a client after the fact, which posture and guest flows lean on. On 10.18 each ClearPass node needs its own client line.

radius dyn-authorization enable
radius dyn-authorization client 192.0.2.10 secret-key plaintext <SHARED-SECRET>
The note on radius dyn-authorization enable

Headless devices get in by what they are

MAC auth for printers, device profiles for APs and phones matched on LLDP. On a port-access port, allow-lldp-bpdu lets that LLDP in before the device has authenticated.

port-access lldp-group APS
    seq 10 match sys-desc AP-515
    exit
port-access device-profile APS
    associate lldp-group APS
    associate role AP-TRUNK
    enable
    exit
The note on port-access device-profile <WORD>

Voice is a VLAN of its own

Mark it voice so LLDP-MED can hand it to phones, tag it on the phone port, keep data native for the PC behind the phone, and make those ports multi-domain.

vlan 30
    name VOICE
    voice
    exit
interface 1/1/1-1/1/20
    aaa authentication port-access auth-mode multi-domain
    exit
The note on voice

Time and logs before anything breaks

Two NTP servers and a syslog server. When something happens overnight, the switch's own log has rolled over by morning and the timestamps are what you correlate on.

ntp server 192.0.2.30 iburst
ntp server 192.0.2.31 iburst
ntp enable
logging 192.0.2.40

Change with a way back

A checkpoint before the change, checkpoint diff before any rollback, and write memory only once the change is proven. Until then a reboot is your rollback.

copy running-config checkpoint before-change
checkpoint diff checkpoint before-change running-config
write memory
The note on checkpoint diff <from> <to>

Stay on a release you have read about

Pick a release the platform supports, read its release notes, and check the Feature Navigator for what it adds. The picker in the sandbox shows what the syntax did in each release.

Hardening, CIS by control number

The CIS HPE Aruba Networking CX Switch Benchmark v1.0.1, Level 1 has 28 automated and manual items. They are mapped here by control number only: the numbers come from the public Tenable audit file for it, the wording is mine, and the benchmark's own text is not reproduced. Where a control can be read from a config, the config checker looks for it; the rest need eyes on the box.

CIS 1.1.1The config checker looks for this

A separate local user group for security staff, allowed to read logs and little else, so nobody needs an admin account to audit.

Check: show user-group

CIS 1.1.2Check this by hand

Passwords and shared secrets are typed at the masked prompt, never inline on the command line where history and the screen keep them.

user admin password
radius-server host 192.0.2.10 key
CIS 1.1.3The config checker looks for this

A password complexity policy: minimum length, a character from each class, and a history so old passwords do not come back.

Check: show password-complexity

password complexity
    minimum-length 14
    lowercase-count 1
    uppercase-count 1
    numeric-count 1
    special-char-count 1
    history-count 5
    enable
    exit
CIS 1.1.4The config checker looks for this

The export password is your own, not the factory default, so secrets exported from this switch do not decrypt on any other CX switch.

Check: show running-config

service export-password
CIS 1.1.6Check this by hand

The built-in admin account has a strong password.

user admin password
CIS 1.1.7Check this by hand

Where the built-in groups do not fit, custom user groups allow only the commands listed in them.

Check: show user-group

CIS 1.1.8The config checker looks for this

CLI sessions are limited per user, close after 15 minutes idle, and login history is kept.

Check: show running-config | begin cli-session

cli-session
    timeout 15
    exit
CIS 1.1.9The config checker looks for this

Telnet stays off on every VRF, which is the default. Remote CLI is SSH only.

Check: show telnet server

no telnet server vrf default
CIS 1.2.2The config checker looks for this

The SSH allow-list is on, so only the management hosts or subnets listed can even try to log in.

Check: show ssh server

ssh server allow-list
    ip 192.0.2.0/24
    enable
    exit
CIS 1.2.6Check this by hand

The SSH host key is regenerated with a strong type: ECDSA nistp256, ed25519, or RSA of 2048 bits.

Check: show ssh host-key

ssh host-key ecdsa ecdsa-sha2-nistp256
CIS 1.3.1The config checker looks for this

NTP is authenticated with a shared key, so the switch only believes time servers that hold it.

Check: show ntp associations

ntp authentication
ntp authentication-key 1 sha1 <NTP-KEY>
ntp trusted-key 1
ntp server 192.0.2.30 key-id 1 iburst
CIS 1.3.2The config checker looks for this

The clock and time zone are set and NTP runs against more than one server.

Check: show ntp status · show clock

clock timezone us/eastern
ntp server 192.0.2.30 iburst
ntp server 192.0.2.31 iburst
ntp enable
CIS 1.4.1.1The config checker looks for this

No SNMP community is public or private, communities are read-only unless write is needed, and an access list limits who may ask.

Check: show snmp community

no snmp-server community public
CIS 1.5.3.1The config checker looks for this

The switch's own role-based rules decide which commands each user may run.

Check: show aaa authorization

aaa authorization commands ssh group local
aaa authorization commands console group local
CIS 1.5.4.1The config checker looks for this

Accounting is also kept on the switch, so the record of who did what survives the AAA server being down.

Check: show aaa accounting

aaa accounting all-mgmt default start-stop local
CIS 1.7.1Check this by hand

Only HPE-signed firmware loads. The switch checks the signature at download and at every boot.

Check: show version

CIS 1.8.1.1The config checker looks for this

Files move to and from the switch with SCP or SFTP, never TFTP.

Check: show running-config | include tftp

CIS 1.9.1The config checker looks for this

The web UI and REST API are only on in the VRFs someone manages the switch from.

Check: show https-server

no https-server vrf default
CIS 1.9.2The config checker looks for this

Web sessions time out as soon as operations allow; five minutes when only people use the web UI.

Check: show https-server

https-server session-timeout 5
CIS 1.10.1The config checker looks for this

ServiceOS asks for a password at the console. Out of the box anyone at the console gets in as admin with none.

Check: show running-config | include serviceos

system serviceos password-prompt
CIS 1.12The config checker looks for this

A banner before login says the switch is for authorized use only.

Check: show banner motd

banner motd ^
Authorized use only. Activity on this switch is logged.
^
CIS 1.13The config checker looks for this

A scheduled job copies the running config off the switch regularly, over SFTP or SCP.

Check: show job · show schedule

CIS 1.14The config checker looks for this

The hostname is unique and says where the switch is.

Check: show system

hostname idf2-sw1
CIS 2.1.2Check this by hand

Factory reset from the front panel button stays off, which is the default, so physical access is not a wipe.

CIS 2.1.3The config checker looks for this

Every port nothing is plugged into is shut down.

Check: show interface brief

interface 1/1/20-1/1/24
    shutdown
    exit
CIS 4.2.1The config checker looks for this

Access ports facing end devices run BPDU guard: a switch plugged in shuts the port.

Check: show spanning-tree

interface 1/1/1-1/1/20
    spanning-tree bpdu-guard
    exit
CIS 4.2.2The config checker looks for this

Ports that should never lead toward the root bridge run root guard.

Check: show spanning-tree

interface 1/1/1-1/1/20
    spanning-tree root-guard
    exit