6.1.2 Ensure Accounting of Logins

Information

When External AAA is used, Login Events should be sent to configured accounting destinations.

Rationale:

To protect any asset, including a Juniper router, you have to have a record of who logged in or attempted to login as well as who made changes to the configuration and when.

JUNOS can log these events to RADIUS and/or TACACS+ servers to allow reliable, centralized records to be kept for all of the devices in your network.

Solution

Configure Accounting of Logins and Configuration Changes by entering the following commands under the [edit system accounting] hierarchy;

[edit system accounting]
user@host#set events login

Default Value:

External accounting is not configured by default

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-12, CSCv7|6.2, CSCv7|6.3

Plugin: Juniper

Control ID: f0d4e723830ece372a64e2d762794e2e6138b9b898448e8dc83e044d3fb73071