Skip to content

Juniper EX Series Switches Router Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000364-RTR-000200

    <GroupDescription></GroupDescription>
    Group
  • The Juniper perimeter router must be configured to drop fragmented IPv6 packets where the first fragment does not include the entire IPv6 header chain.

    &lt;VulnDiscussion&gt;One of the fragmentation weaknesses known in IPv6 is the "undetermined transport" packet, which is the first fragment where t...
    Rule Medium Severity
  • SRG-NET-000364-RTR-000201

    <GroupDescription></GroupDescription>
    Group
  • The Juniper perimeter router must be configured drop IPv6 packets with a Routing Header type 0, 1, or 3255.

    &lt;VulnDiscussion&gt;The routing header can be used maliciously to send a packet through a path where less robust security is in place, rather tha...
    Rule Medium Severity
  • SRG-NET-000364-RTR-000202

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules