Access Security - J-Web - Terminate idle connections by setting the idle-time value

Information

Enabling a session's idle timeout is always a good security practice to reduce the chances of unattended sessions being used by unauthorized users.

Solution

Configure J-Web over HTTPS to time out idle sessions.

user@host# edit system services web-management session
user@host# set idle-timeout 5

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CSCv6|16.4

Plugin: Juniper

Control ID: 11f22100ad598d8044a9a2cf62f6f4f1a9f9ea1e3494a5a00e0d7119a60a19d0