6.11.1 Ensure Auxiliary Port is Set to Disabled

Information

The Auxiliary Port should be disabled when not required.

Rationale:

The Auxiliary Port on a Juniper Device is used to connect Modems and other devices to allow remote administration of the router when other connectivity is not possible.

Connections to the Auxiliary Port are treated in a very similar fashion to local Console Port connections.

Although this is a useful function, in most deployments the Auxiliary Port is not utilized at all and so should be disabled, which is the default in all current Junos versions, to prevent potential abuse.

Impact:

The Auxiliary port will not be available.

Solution

To disable the Auxiliary Port, issue the following command from the [edit system ports] hierarchy;

[edit system ports]
user@host#set auxiliary disable

Default Value:

The Auxiliary port is disabled by default on most current platforms.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: cb1ed0ef3b93cd5200a108436dcb46047d01bf5e1aea36b1192914c7ce24ecaf