STIGQter STIGQter: STIG Summary: Juniper SRX Services Gateway VPN Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 30 Jan 2025:

The Juniper SRX Services Gateway VPN must be configured to use Diffie-Hellman (DH) group 15 or higher.

DISA Rule

SV-214674r1056179_rule

Vulnerability Number

V-214674

Group Title

SRG-NET-000062

Rule Version

JUSX-VN-000007

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

The following command is an example of how to configure the IKE (phase 1) proposals.

Example:
[edit]
set security ike proposal <P1-PROPOSAL-NAME> dh-group group19

Check Contents

Verify all IKE proposals are set to use a FIPS-validated dh-group.

[edit]
show security ike <P1-PROPOSAL-NAME>

View the IKE options dh-group option.

If the IKE option is not set to a FIPS 140-2/140-3 validated dh-group, this is a finding.

Vulnerability Number

V-214674

Documentable

False

Rule Version

JUSX-VN-000007

Severity Override Guidance

Verify all IKE proposals are set to use a FIPS-validated dh-group.

[edit]
show security ike <P1-PROPOSAL-NAME>

View the IKE options dh-group option.

If the IKE option is not set to a FIPS 140-2/140-3 validated dh-group, this is a finding.

Check Content Reference

M

Target Key

4009