1.9.1 https-server default enablement

Information

On AOS-CX, the https-server is enabled by default allowing customers to access the device via its REST API or Web interface (WebUI). On campus products, the https-server is enabled on the default VRF. Products with an OOBM interface also have the https-server enabled on the mgmt VRF.

Customers should be aware of this default enablement so that they can account for enabled management interfaces.

Solution

Customers that do not wish to have the https-server enabled can disable it using the following:

switch(config)# no https-server vrf <VRF-NAME>

Impact:

Lack of knowledge of enabled management interfaces can result in unexpected access of a network device.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: ArubaOS

Control ID: 94081e7578f66af5abffe514bf5f6cb7bc0b1d13c6dbe2d65b721fd3fd8777ae