2.1.1 Disable USB and Bluetooth on Device

Information

Disable USB Auxiliary port

The AOS-CX switch front-panel includes an USB Auxiliary port for the following purposes:

- USB Mass storage - flash drive for deploying, troubleshooting, backing up configurations, or upgrading switches
- Bluetooth Adapter - allows Bluetooth enabled devices to connect to and manage the switch on a wireless Bluetooth Personal Area Network (PAN)

The Bluetooth feature has been enabled by default in AOS-CX switches and designed for operational simplicity. The switch provides an IP address to paired devices though DHCP when they join the Bluetooth Personal Area Network. Paired devices can then manage the switch through following methods:

- SSH
- Web UI
- REST API
- Aruba CX Mobile App

Solution

switch(config)# no usb switch(config)# bluetooth disable

Impact:

Disabling USB will prevent both USB devices from being mounted and Bluetooth adapters form being enabled.

Disabling Bluetooth will only prevent Bluetooth adapters from being enabled.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: CONFIGURATION MANAGEMENT, MEDIA PROTECTION

References: 800-53|CM-6, 800-53|CM-7, 800-53|MP-5, 800-53|MP-7, CSCv7|13.7, CSCv7|15.9

Plugin: ArubaOS

Control ID: 966f65159166ee9cd365101841e53c9118aedc4ea06a81ad550664efb18a93e7