6.6.1.1 Ensure Max 3 Failed Login Attempts

Information

A maximum of 3 failed login attempts should be allowed before the session is disconnected.

Rationale:

Remote administration protocols like Telnet and SSH are commonly targeted by Brute Force or Dictionary attacks where a malicious user attempts to guess a valid username/password combination in order to gain control of the router. To slow down the rate at which an attacker can attempt to guess passwords, sessions should be disconnected after no more than 3 failed login attempts (a lower value can be used if preferred).

Solution

Configure the number of tried before disconnect using the following command under the [edit system] hierarchy:

[edit system]
user@host#set login retry-options tries-before-disconnect

Default Value:

For most JUNOS version the default is to disconnect after 10 failed login attempts.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|16

Plugin: Juniper

Control ID: 0ed97b4b95e6bb850c3a90cf91c12afcdddf6081a249768c5ffdf58d5f8c4a17