User Authentication Security - Configure login security options to hinder password guessing attacks - backoff-threshold

Information

The Junos default behavior for login security provides reasonable protection from password guessing attacks, but may not be suitable for every environment.

Set the threshold for the number of failed login attempts before the user experiences a delay between login attempts. The range is from 1 through 3, with a default of 2.

Solution

Configure login security for the number of failed login attempts before delays are introduced.

user@host# edit system login retry-options
user@host# set backoff-threshold 1

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a.

Plugin: Juniper

Control ID: afc861d20bc3f2b41cf0ffeca7b0e61b2f2f429af2a057ebcf37930c59558431