Firewall Filter - Order terms with time sensitive protocols at the top

Information

Firewall filters are processed in order from the top to the bottom. Although most Junos platforms process firewall filters in hardware at line rate, it's always a best practice to order your terms so that time sensitive protocols, like routing protocols, are positioned close to the top of the filter.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the system configuration to verify the order of the firewall rules allow for time sensitive protocols to be applied first.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11)

Plugin: Juniper

Control ID: c0c1b504da08656ba3d9c99950bc2259d9210292f0ea4e53ba87b19bb6e1cd82