Juniper SRX Services Gateway NDM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000506-NDM-000323
Group -
The Juniper SRX Services Gateway must generate log records when concurrent logons from different workstations occur.
Without generating log records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an inci...Rule Low Severity -
SRG-APP-000101-NDM-000231
Group -
SRG-APP-000357-NDM-000293
Group -
SRG-APP-000360-NDM-000295
Group -
SRG-APP-000374-NDM-000299
Group -
The Juniper SRX Services Gateway must record time stamps for log records using Coordinated Universal Time (UTC).
If time stamps are not consistently applied and there is no common time reference, it is difficult to perform forensic analysis. UTC is normally used in DoD; however, Greenwich Mean Time (GMT) may ...Rule Medium Severity -
SRG-APP-000378-NDM-000302
Group -
SRG-APP-000516-NDM-000317
Group -
If the loopback interface is used, the Juniper SRX Services Gateway must protect the loopback interface with firewall filters for known attacks that may exploit this interface.
The loopback interface is a logical interface and has no physical port. Since the interface and addresses ranges are well-known, this port must be filtered to protect the Juniper SRX from attacks.Rule Medium Severity -
SRG-APP-000516-NDM-000317
Group -
The Juniper SRX Services Gateway must have the number of rollbacks set to 5 or more.
Backup of the configuration files allows recovery in case of corruption, misconfiguration, or catastrophic failure. The maximum number of rollbacks for the SRX is 50 while the default is 5 which is...Rule Low Severity -
SRG-APP-000373-NDM-000298
Group -
SRG-APP-000516-NDM-000336
Group -
The Juniper SRX Services Gateway must be configured to use an authentication server to centrally manage authentication and logon settings for remote and nonlocal access.
Centralized management of authentication settings increases the security of remote and nonlocal access methods. This control is a particularly important protection against the insider threat. Audit...Rule Medium Severity -
SRG-APP-000516-NDM-000344
Group -
SRG-APP-000142-NDM-000245
Group -
SRG-APP-000142-NDM-000245
Group -
SRG-APP-000142-NDM-000245
Group -
SRG-APP-000142-NDM-000245
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.