3.3 Ensure unused interfaces are set to disable

Information

Unused interfaces should be explicitly disabled.

Rationale:

JUNOS routers can be installed with tens or even hundreds of physical interfaces of different types. To ensure that unused interfaces are not connected to networks, either accidently or by a malicious user seeking to bypass security measures, all unused interfaces should be explicitly disabled.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To disable an interface enter the following command from the [edit interfaces <interface name>] hierarchy.

[edit interfaces <interface name>]
user@host#set disable

Default Value:

Installed physical interfaces are enabled by default on most platforms.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: 3872fd9f89e75ef7154c8be7df690fd2330db76c07703c0b4dfccec4becbe6b7