User Authentication Security - Configure login security options to hinder password guessing attacks - minimum-time

Information

The Junos default behavior for login security provides reasonable protection from password guessing attacks, but may not be suitable for every environment.

Limit the minimum length of time in seconds that the connection remains open while the user is attempting to enter a password to log in. The range is from 20 through 60. The default setting is 20.

Solution

Configure login security for minimum amount of time a login attempt has before disconnect.

user@host# edit system login retry-options
user@host# set minimum-time 15

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a.

Plugin: Juniper

Control ID: cff31c73cc151a82c1c416af635a0376894f3945acc0f48b36f8ba20a3996d79