Item Search

NameAudit NamePluginCategory
1.4 Ensure configuration is backed up on a regular scheduleCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONTINGENCY PLANNING

1.38 CISC-ND-001270CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.51 CISC-RT-000500CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

ACCESS CONTROL

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

4.3.2 Ensure OSPF authentication is set to IPSEC SA with SHACIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

4.3.2.5 Ensure gated is not in useCIS IBM AIX 7 v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

4.4.1 Ensure OSPFv3 authentication is set to IPSEC SA - md5CIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

4.6.2 Ensure BFD Authentication is Not Set to Loose-CheckCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

5.7 Ensure SHA1 is set for SNMPv3 authenticationCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.4.2 Ensure Diagnostic Port Authentication uses a complex passwordCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.5.1 Ensure ICMPv4 rate-limit is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.6.5 Ensure all Custom Login Classes Forbid Shell AccessCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.6.13 Ensure SSH Key Authentication is not set for User LoginsCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.8.2 Ensure Share-Secret is set for External AAA ServersCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.8.3 Ensure a Different Shared Secret is Set for each External AAA ServerCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.9.1 Ensure a complex Root Password is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.10 Ensure Only Suite B Key Exchange Methods are set for SSH - key-exchange restrictionCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.2.3 Ensure Web-Management is Set to use PKI Certificate for HTTPSCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.3.3 Ensure XNM-SSL Rate Limit is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.10.5.5 Ensure REST HTTPS Cipher List is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.12.2 Ensure At Least 2 External SYSLOG Hosts are Set with Any/InfoCIS Juniper OS Benchmark v2.1.0 L2Juniper

AUDIT AND ACCOUNTABILITY

6.12.5 Ensure Local Logging is Set for Interactive-CommandsCIS Juniper OS Benchmark v2.1.0 L1Juniper

AUDIT AND ACCOUNTABILITY

6.14 Ensure Configuration File Encryption is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.15 Ensure Multicast Echo is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - ftpJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - rshJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - J-Web - Limit access to only authorized interfacesJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Allow SNMP queries and/or send traps to more than one trusted serverJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Configure read-only access; use read-write only when requiredJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Management Services Security - Configure SNMP using the most secure method with more than one trusted server - v1/v2 not configuredJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Network Security - Disable ICMP timestamp & record route requests - no-ping-record-routeJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Network Security - Drop TCP packets with the SYN and FIN flag combinationJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Physical Security - Auxiliary Port - Configure the insecure featureJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Physical Security - Auxiliary Port - Disable the Auxiliary portJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Physical Security - Console Port - Configure the insecure featureJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Physical Security - Craft Interface/LCD Menu - Disable unnecessary functions for your environment - config-button no-clearJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Physical Security - Craft Interface/LCD Menu - Disable unnecessary functions for your environment - craft-lockoutJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Routing Protocol Security - BGP communication should source from a loopback interfaceJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Routing Protocol Security - Use strong authentication keys that meet your organization's password complexity policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Centralized authentication - Configure accounting to trace activity and usageJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Centralized authentication - Configure multiple servers for resiliency - RadiusJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Centralized authentication - Create an emergency local account in the event authentication is unavailableJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Configure a password complexity policy - all character-sets are enforcedJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure a password complexity policy - Lower case charactersJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure a password complexity policy - Minimum password lengthJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure login security options to hinder password guessing attacks - tries-before-disconnectJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Local Authentication - Know the origin and purpose for all configured local accountsJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Local Authentication - Set the authentication-order to meet your login security policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION