STIGQter STIGQter: STIG Summary: Juniper Router NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 24 Jul 2020:

The Juniper router must be configured to off-load log records onto a different system than the system being audited.

DISA Rule

SV-101285r1_rule

Vulnerability Number

V-91185

Group Title

SRG-APP-000515-NDM-000325

Rule Version

JUNI-ND-001300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the router to send log records to a syslog server as shown in the example below.

[edit system]
set syslog host x.x.x.x any info

Check Contents

Review the router configuration to verify that it is compliant with this requirement as shown in the example below.

system {
syslog {
host x.x.x.x {
any info;
}
}

If the router is not configured to off-load log records onto a different system than the system being audited, this is a finding.

Vulnerability Number

V-91185

Documentable

False

Rule Version

JUNI-ND-001300

Severity Override Guidance

Review the router configuration to verify that it is compliant with this requirement as shown in the example below.

system {
syslog {
host x.x.x.x {
any info;
}
}

If the router is not configured to off-load log records onto a different system than the system being audited, this is a finding.

Check Content Reference

M

Target Key

3381

Comments