Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - tftp-server

Information

Access services are considered insecure when communication to the device is unencrypted. Clear-text communications are susceptible to sniffing, replay, and packet capture attacks.

Solution

Disable tftp as an insecure service.

user@host# edit system services
user@host# delete tftp-server

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Juniper

Control ID: 91708e51641f05c544b33d5b935e5b791fe2e6b8aa333fd407275ab5b0766c1d