Item Search

NameAudit NamePluginCategory
2.3 Ensure 'Protect RE' Firewall filter includes Rate-Limiting for Management Services termsCIS Juniper OS Benchmark v2.1.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure firewall filters contain explicit deny and log termCIS Juniper OS Benchmark v2.1.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

2.7 Ensure internal sources are blocked on external networksCIS Juniper OS Benchmark v2.1.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

3.6 Ensure ICMP Redirects are set to disabled (on all untrusted IPv4 networks)CIS Juniper OS Benchmark v2.1.0 L1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

4.1.4 Ensure Bogon Filtering is set (where EBGP is used)CIS Juniper OS Benchmark v2.1.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.3 Ensure authentication check is not suppressedCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

4.2.5 Ensure IS-IS Hello authentication check is not suppressedCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

4.9.1 Ensure Secure Neighbor Discovery is configuredCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure at least one SCP Archive Site is configuredCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONTINGENCY PLANNING

6.5.2 Ensure ICMPv6 rate-limit is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.5.5 Ensure TCP RST is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.6.1.5 Ensure Lockout-period is set to at least 30 minutesCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.6.2 Ensure Login Class is set for all Users AccountsCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.6.3 Ensure Idle Timeout is set for all Login ClassesCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.6.8 Ensure login message is setCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.8 Ensure VPC Endpoints are used for access to AWS ServicesCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

6.8.1 Ensure External AAA Server is setCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.5 Ensure Remote Root-Login is denied via SSHCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.10.1.7 Ensure Only Suite B Ciphers are set for SSH - weak ciphersCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.8 Ensure Strong MACs are set for SSHCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.9 Ensure Strong Key Exchange Methods are set for SSHCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.12 Ensure Only Suite B Based Key Signing Algorithms are set for SSH - DSA keysCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.13 Ensure SSH Key Authentication is DisabledCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.2.6 Ensure Web-Management Interface Restriction is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

6.10.5.4 Ensure REST HTTPS is Set to use Mutual AuthenticationCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.5.11 Ensure REST Service Address is Set to OOB Management OnlyCIS Juniper OS Benchmark v2.1.0 L2Juniper

ACCESS CONTROL

6.10.7 Ensure Reverse Telnet is Not SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

6.10.10 Ensure Unused DHCP Service is Not SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.19 Ensure Hostname is Not Set to Device Make or ModelCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

106.2.1.1 Ensure 'System Security: Device Security: Firewall' is set to 'Require'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Access Security - Configure a warning banner that is displayed prior to loginJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - rloginJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Enable required secure access services - sshJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Access Security - J-Web - Use HTTPS with a valid certificate signed by a trusted CA - local-certificateJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Access Security - SSH - Set connection-limit and rate-limit restrictions - rate-limitJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Firewall Filter - Ensure the last term, default-deny, includes the syslog optionJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Firewall Filter - Permit only required protocols from authorized sourcesJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Firewall Filter - Rate-limit authorized protocols using policersJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Firewall Filter - Rate-limit SYN packets to protect against a SYN flood attackJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Allow SNMP queries and/or send traps to more than one trusted server - usm trapsJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Community strings and USM passwords should be difficult to guess and should follow a policy - usmJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Management Services Security - Configure NTP with authentication with more than one trusted server - multiple serversJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Send Syslog messages to more than one trusted server with enhanced timestampsJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

OH12-1X-000031 - OHS must have the Order, Allow, and Deny directives set within the Directory directives set to restrict inbound connections from nonsecure zones.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000032 - OHS must have the Order, Allow, and Deny directives set within the Files directives set to restrict inbound connections from nonsecure zones.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

Physical Security - Diagnostic Ports - Password protect Diagnostic ports - diag-portJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Routing Protocol Security - Periodically change route authentication keys in accordance with your organization's security policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Centralized authentication - Configure accounting to trace activity and usage - TACACS+Juniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Centralized authentication - Configure multiple servers for resiliency - TACACS+Juniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure login security options to hinder password guessing attacks - minimum-timeJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL