JUSX-IP-000030 - The Juniper Networks SRX Series Gateway IDPS must have only active Juniper Networks licenses.

Information

If the IDP or UTM licenses are allowed to lapse, the Juniper SRX IDPS can still inspect traffic and continue to use the outdated signature database for rules, objects, and dynamic groups. However, updates to the signature database cannot be downloaded from Juniper Networks. This puts the network at risk since the updates are used to addresses new CERT and IAVM vulnerabilities.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Update the expired licenses immediately following the procedures on the vendor website.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_SRX_SG_Y22M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-80929r1_rule, STIG-ID|JUSX-IP-000030, Vuln-ID|V-66439

Plugin: Juniper

Control ID: 4559a88a496781de2b0986d8d9707e83cac8e5566be9ccc8f02e5b260816871c