Firewall Filter - Rate-limit authorized protocols using policers

Information

Rate-limiting provides another layer of protection in a filter. In addition to allowing only specific protocols from specific hosts, you can also rate limit the amount of allowed traffic to reasonable levels, ensuring that authorized hosts cannot flood the Routing Engine.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the system configuration to verify that authorized protocols are rate limited with policiers.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-6

Plugin: Juniper

Control ID: 359145bd7916ab9c22763f770f8c3d0a08831abbc812b628d9cc2bbec0641d0a