1.6 Ensure maximum RAM is installed

Information

The router should have the maximum RAM installed.

Rationale:

Some Denial of Service attacks rely on exhausting the target routers memory resources by bombarding the router with bogus requests or traffic, when the router runs out of memory it will stop being able to service genuine requests and may be unable to perform critical tasks like maintaining route tables.

Juniper routers are somewhat more resilient to this type of attack then some other systems due to the separation of the Control and Forwarding planes, but attacks against router services may still cause disruption.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Installing the most RAM available for your system will both help to mitigate these attacks and boost performance of your routers. In most cases RAM upgrades are extremely cost effective way to increase router performance and survivability.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|11

Plugin: Juniper

Control ID: a999d51ddb1e60f078c13ee0d95713657317ce4b64680b0896aec87d10ce4f50