STIGQter STIGQter: STIG Summary: Juniper SRX Services Gateway ALG Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

The Juniper SRX Services Gateway Firewall must disable or remove unnecessary network services and functions that are not used as part of its role in the architecture.

DISA Rule

SV-214523r557389_rule

Vulnerability Number

V-214523

Group Title

SRG-NET-000131-ALG-000085

Rule Version

JUSX-AG-000083

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove unnecessary services and functions. From operational mode, display the licenses available to be deleted; enter the following commands.

request system license delete license-identifier-list ?
request system license delete <license-identifier>

Note: Only remove unauthorized services. This control is not intended to restrict the use of Juniper SRX devices with multiple authorized roles.

Check Contents

Review the documentation and architecture for the device.

<root>
show system license

If unneeded services and functions are installed on the device, but are not part of the documented role of the device, this is a finding.

Vulnerability Number

V-214523

Documentable

False

Rule Version

JUSX-AG-000083

Severity Override Guidance

Review the documentation and architecture for the device.

<root>
show system license

If unneeded services and functions are installed on the device, but are not part of the documented role of the device, this is a finding.

Check Content Reference

M

Target Key

4004

Comments