Skip to content

Juniper EX Series Switches Network Device Management Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000096-NDM-000226

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000001-NDM-000200

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to limit the number of concurrent management sessions to 10 or an organization-defined value.

    &lt;VulnDiscussion&gt;Device management includes the ability to control the number of administrators and management sessions that manage a device. ...
    Rule Medium Severity
  • SRG-APP-000026-NDM-000208

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to automatically audit account creation.

    &lt;VulnDiscussion&gt;Upon gaining access to a network device, an attacker will often first attempt to create a persistent method of reestablishing...
    Rule Medium Severity
  • SRG-APP-000033-NDM-000212

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to assign appropriate user roles or access levels to authenticated users.

    &lt;VulnDiscussion&gt;Successful identification and authentication must not automatically give an entity full access to a network device or securit...
    Rule High Severity
  • SRG-APP-000038-NDM-000213

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.

    &lt;VulnDiscussion&gt;A mechanism to detect and prevent unauthorized communication flow must be configured or provided as part of the system design...
    Rule Medium Severity
  • SRG-APP-000065-NDM-000214

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce the limit of three consecutive invalid logon attempts for any given user, after which time it must block any login attempt for that user for 15 minutes.

    &lt;VulnDiscussion&gt;By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise...
    Rule Medium Severity
  • SRG-APP-000068-NDM-000215

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.

    &lt;VulnDiscussion&gt;Display of the DOD-approved use notification before granting access to the network device ensures privacy and security notifi...
    Rule Medium Severity
  • SRG-APP-000095-NDM-000225

    <GroupDescription></GroupDescription>
    Group
  • The Juniper device must be configured to produce audit log records containing sufficient information to establish what type of event occurred.

    &lt;VulnDiscussion&gt;It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, a...
    Rule Medium Severity
  • The Juniper EX switch must be configured to produce audit records containing information to establish when (date and time) the events occurred.

    &lt;VulnDiscussion&gt;It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, a...
    Rule Medium Severity
  • SRG-APP-000097-NDM-000227

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to produce audit records containing information to establish where the events occurred.

    &lt;VulnDiscussion&gt;To compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know where ev...
    Rule Medium Severity
  • SRG-APP-000098-NDM-000228

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to produce audit log records containing information to establish the source of events.

    &lt;VulnDiscussion&gt;To compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know the sour...
    Rule Medium Severity
  • SRG-APP-000099-NDM-000229

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to produce audit records that contain information to establish the outcome of the event.

    &lt;VulnDiscussion&gt;Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attac...
    Rule Medium Severity
  • SRG-APP-000100-NDM-000230

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to generate audit records containing information that establishes the identity of any individual or process associated with the event.

    &lt;VulnDiscussion&gt;Without information that establishes the identity of the subjects (i.e., administrators or processes acting on behalf of admi...
    Rule Medium Severity
  • SRG-APP-000119-NDM-000236

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to protect audit information from unauthorized modification.

    &lt;VulnDiscussion&gt;Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully au...
    Rule Medium Severity
  • SRG-APP-000120-NDM-000237

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to protect audit information from unauthorized deletion.

    &lt;VulnDiscussion&gt;Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully au...
    Rule Medium Severity
  • SRG-APP-000121-NDM-000238

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to protect audit tools from unauthorized access.

    &lt;VulnDiscussion&gt;Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Therefore, pro...
    Rule Medium Severity
  • SRG-APP-000133-NDM-000244

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to limit privileges to change the software resident within software libraries.

    &lt;VulnDiscussion&gt;Changes to any software components of the network device can have significant effects on the overall security of the network....
    Rule Medium Severity
  • SRG-APP-000142-NDM-000245

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

    &lt;VulnDiscussion&gt;To prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embeddi...
    Rule High Severity
  • SRG-APP-000148-NDM-000346

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

    &lt;VulnDiscussion&gt;Authentication for administrative (privileged level) access to the device is required at all times. An account is created on ...
    Rule Medium Severity
  • SRG-APP-000156-NDM-000250

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.

    &lt;VulnDiscussion&gt;A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authen...
    Rule Medium Severity
  • SRG-APP-000164-NDM-000252

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce a minimum 15-character password length.

    &lt;VulnDiscussion&gt;Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute...
    Rule Medium Severity
  • SRG-APP-000166-NDM-000254

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000395-NDM-000347

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.

    &lt;VulnDiscussion&gt;Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity,...
    Rule Medium Severity
  • SRG-APP-000167-NDM-000255

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce password complexity by requiring that at least one lowercase character be used.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • SRG-APP-000168-NDM-000256

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce password complexity by requiring that at least one numeric character be used.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • SRG-APP-000169-NDM-000257

    <GroupDescription></GroupDescription>
    Group
  • The Juniper EX switch must be configured to enforce password complexity by requiring that at least one punctuation (special) character be used.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • SRG-APP-000170-NDM-000329

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules