Management Services Security - Community strings and USM passwords should be difficult to guess and should follow a password policy

Information

It's a best security practice to use complex community strings and to change them periodically since they are transmitted in plain-text and susceptible to capture.

The Junos SNMPv3 implementation supports various hashing and encryption algorithms - obviously the strongest methods provide maximum security but you have to choose algorithms and encryption that are supported by your management stations.

NOTE: SNMP does not appear to be configured.

Solution

If SNMP is not required, keep it not configured.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5

Plugin: Juniper

Control ID: 6807b50cdf9754ba2a42a8e7dbfce2aa7ad8dcd184d1730745c4db649dff98b7