User Authentication Security - Configure custom login classes to support engineers with different access levels using least privilege

Information

In Junos software user privileges are defined in a login class. All users that log in to a Junos device must be assigned a login class. Login classes allow you to define the following:
* Access privileges when the user logs in to the device
* Commands and statements that the user can and cannot execute
* Other useful options such as time-based enforcement, idle time, and displaying system alarms on login

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the system configuration that there are multiple login classes and that engineers are assigned to the proper class in support of least privilege principle.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1)

Plugin: Juniper

Control ID: 3fd6002bbdc8c84fd6a7d2361a3a4c99f7c19e7c6283c7a3f3392fe464598f9f