Item Search

NameAudit NamePluginCategory
1.8 Ensure Retired JUNOS Devices are Disposed of SecurelyCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

3.4 Ensure interface description is setCIS Juniper OS Benchmark v2.1.0 L1Juniper

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT

4.1.2 Ensure peer authentication is set to IPSEC SACIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

4.12.1 Ensure LLDP is Disabled if not RequiredCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

4.12.2 Ensure LLDP-MED is Disabled if not RequiredCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

5.3 Ensure a client list is set for SNMPv1/v2 communitiesCIS Juniper OS Benchmark v2.1.0 L1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

5.26 (L1) Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

6.2.3 Ensure NO Plain Text Archive Sites are configuredCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONTINGENCY PLANNING

6.5.3 Ensure ICMP Source-Quench is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.6.6 Ensure Predefined Login Classes are not usedCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.7.7 Ensure Strong Authentication Methods are used for NTP AuthenticationCIS Juniper OS Benchmark v2.1.0 L2Juniper

AUDIT AND ACCOUNTABILITY

6.10.1.4 Ensure SSH Rate Limit is ConfiguredCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.7 Ensure Only Suite B Ciphers are set for SSH - ciphers restrictionCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.12 Ensure Only Suite B Based Key Signing Algorithms are set for SSH - ECDSA KeyCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.2.4 Ensure Idle Timeout is Set for Web-ManagementCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.2.5 Ensure Session Limited is Set for Web-ManagementCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.2.7 Ensure Web-Management Interface Restriction is set to OOB ManagementCIS Juniper OS Benchmark v2.1.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

6.10.3.4 Ensure XNM-SSL SSLv3 Support is Not SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.4.2 Ensure NETCONF Connection Limit is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.10.5.1 Ensure REST is Not Set to HTTPCIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.5.10 Ensure REST Service Address is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL, CONFIGURATION MANAGEMENT

6.10.6 Ensure Telnet is Not SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

6.11.4 Ensure Console Port is Set as InsecureCIS Juniper OS Benchmark v2.1.0 L2Juniper

ACCESS CONTROL

6.11.5 Ensure Log-out-on-disconnect is Set for ConsoleCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.12.1 Ensure External SYSLOG Host is Set with Any Facility and Informational SeverityCIS Juniper OS Benchmark v2.1.0 L1Juniper

AUDIT AND ACCOUNTABILITY

6.12.6 Ensure Local Logging is Set to Messages FileCIS Juniper OS Benchmark v2.1.0 L1Juniper

AUDIT AND ACCOUNTABILITY

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - J-Web over HTTPJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - tftp-serverJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - J-Web - Use HTTPS with a valid certificate signed by a trusted CA - trusted CAJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Access Security - SSH - Use SSH version 2Juniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

ARST-L2-000220 - The Arista MLS layer 2 switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.DISA STIG Arista MLS EOS 4.2x L2S v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

Firewall Filter - Order terms with time sensitive protocols at the topJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Allow SNMP queries and/or send traps to more than one trusted server - clients restrictJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Configure automated secure configuration backups to more than one trusted server - archive-sitesJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONTINGENCY PLANNING

Management Services Security - Configure NTP with authentication with more than one trusted server - authentication valueJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Configure NTP with authentication with more than one trusted server - trusted-keyJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Configure read-only access; use read-write only when required - communityJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Management Services Security - Configure read-only access; use read-write only when required - usmJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Management Services Security - Configure SNMP using the most secure method with more than one trusted serverJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Network Security - Disable ICMP Source Quench - no-source-quenchJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Network Security - Set the source address for all route engine generated traffic - syslogJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Network Security - Use the Out-of-Band (OOB) interface for all management related trafficJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Physical Security - Console Port - Configure the logout-on-disconnect featureJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Routing Protocol Security - Select the strongest algorithm that is supported by your equipment and your neighbors - ISISJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

User Authentication Security - Centralized authentication - Use a strong shared secret that complies with your organization's policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure a password complexity policy - Numeric charactersJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure custom login classes to support engineers with different access levels using least privilegeJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Configure login security options to hinder password guessing attacks - lockout-periodJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Ensure the root account has been configured with a strong passwordJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Restrict commands by job functionJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL