Physical Security - Diagnostic Ports - Password protect Diagnostic ports - diag-port

Information

Some hardware modules, such as the System Control Board (SCB), System and Switch Board (SSB), Switching and Forwarding Module (SFM), and Forwarding Engine Board (FEB), have a special port that can be used for advanced diagnostics. By default, diagnostic ports are not secured by a password, which makes it possible for an unauthorized user with physical access to the device to gain access to the system and possibly obtain sensitive network specific information.

Solution

Configure a secure password on the diagnostic port.

user@host# edit system diag-port-authentication
user@host# set encrypted-password <PASSWORD>

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Juniper

Control ID: 3b64cd81d4147c255342cc350f36804f93a7d9b52b95c1cf6d62ed33f8259a7b