Common Criteria for HP Networking Switches

20
USB Port
The switch includes a USB port to receive a flash drive for deploying, troubleshooting, backing up
configurations, or updating switches. This port should be disabled when not in use. The port can be
temporarily enabled when needed and then immediately disabled after the required task is completed.
To disable the port, use the switch’s no usb-port CLI command.
HP Switch # no usb-port
To enable the port, use the usb-port command.
HP Switch # usb-port
Conclusion
The security features described by this white paper are an excellent starting point for hardening HP
networks, and should be used in the context of an organization's greater security policy. Good security
practice dictates that an organization have a well-thought security policy that relies on a thorough
threat assessment and defense-in-depth strategy. Only after creating a security policy can an
organization best capitalize on the many security features present in HP switches, such as MAC
lockdown, DHCP protection, BPDU Port Protection and Dynamic IP Lockdown.