User Authentication Security - Configure login security options to hinder password guessing attacks - backoff-factor

Information

The Junos default behavior for login security provides reasonable protection from password guessing attacks, but may not be suitable for every environment.

Define the delay time after each failed login attempt in seconds. The delay increases by this value for each subsequent login attempt after the value specified in the backoff-threshold option. The range is from 5 through 10. The default is 5.

Solution

Configure login security for the delay introduced between failed login attempts.

user@host# edit system login retry-options
user@host# set backoff-factor 7

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a.

Plugin: Juniper

Control ID: a4125467c1628ffa6e912395a9d7df24acd20c22784e2e3d4d60f1096133b1e2