Comware Based
1753701 Members
5210 Online
108799 Solutions
New Discussion

Disable AUX port on HPE 5800

 
SOLVED
Go to solution
AjinS
Occasional Contributor

Disable AUX port on HPE 5800

Hello,

As per auditing requirement, it is recommended to disable AUX port on our HPE 5800 switches. 

1. How do I disable the aux port?

2. Can I access the switch using console after disabling aux port?

Please advise. Is Aux and Console port same?

Thanks,

Ajin.

6 REPLIES 6
Ivan_B
HPE Pro

Re: Disable AUX port on HPE 5800

Hi @AjinS !

AFAIK aux0 is the console port itself on 5800. If this is not the case, tell me the DEVICE_NAME from the 'display device manuinfo' output.

 

I am an HPE employee

Accept or Kudo

AjinS
Occasional Contributor

Re: Disable AUX port on HPE 5800

Thanks, is it possible to disable the port?

 

Ivan_B
HPE Pro

Re: Disable AUX port on HPE 5800

Of course it's not possible. This port is your only access to the swtich if it loses network connection or something goes wrong during a software update. I am afraid your security auditors don't fully understand how this port works and why it is crucial to keep it up. Did they assess a possibility of locking the port using AAA? Just put authentication on the port and it won't be accessible to unauthorized personnel.

 

I am an HPE employee

Accept or Kudo

AjinS
Occasional Contributor

Re: Disable AUX port on HPE 5800

Thank you Ivan. It's already password protected. Please see the recommendation from audit team below.

"We recommend that the AUX port should be disabled wherever the remote administration support is not required. If the AUX port is required for operational purposes, the call-back facility should be configured as an additional level of protection"

Is call-back facility configuration possible?

Thanks,

Ivan_B
HPE Pro
Solution

Re: Disable AUX port on HPE 5800

Again, they don't understand what is AUX port in 5800. Those guys think that 5800 is like an old Cisco switch where you have console port (to connect a management station directly with a console cable) and AUX (auxillary) port which is used to connect CSU/DSU or in other words modem in order to get a remote access to the switch. I am sure they think the AUX port in 5800 is like the AUX port in Cisco, because they mention 'remote administration' and 'call-back facility'. But the thing is IS NOT. The AUX port in 5800 is the only console port available. It is not used for 'remote administration', like additional AUX port in Cisco.

Therefore as you CANNOT disable con0 port in Cisco IOS-based switch, same way you CANNOT disable aux0 port in 5800. I know the 'aux' term confuses people, maybe that's why in Comware 7 that port is named 'con0', but try to explain this to your auditors, I am sure they will understand the situation and will adapt their recommendation accordingly.

 

 

I am an HPE employee

Accept or Kudo

AjinS
Occasional Contributor

Re: Disable AUX port on HPE 5800

Thank you Ivan...Clear now.