STIGQter STIGQter: STIG Summary: Juniper SRX Services Gateway VPN Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 30 Jan 2025:

If IDPS inspection is performed separately from the Juniper SRX Services Gateway VPN device, the VPN must route sessions to an IDPS for inspection.

DISA Rule

SV-214678r864169_rule

Vulnerability Number

V-214678

Group Title

SRG-NET-000512

Rule Version

JUSX-VN-000011

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Juniper SRX to route traffic to the port attached to intrusion detection system or configure to route all inbound traffic to the sites intrusion detection system using the IP address of the IPS/IDS.

Check Contents

Inspect the Juniper SRX configuration or the site's architecture drawings to verify all inbound VPN traffic is routed to the site's intrusion detection system.

If all inbound VPN traffic is not inspected by the site's IDPS prior to being routed to its destination, this is a finding.

Vulnerability Number

V-214678

Documentable

False

Rule Version

JUSX-VN-000011

Severity Override Guidance

Inspect the Juniper SRX configuration or the site's architecture drawings to verify all inbound VPN traffic is routed to the site's intrusion detection system.

If all inbound VPN traffic is not inspected by the site's IDPS prior to being routed to its destination, this is a finding.

Check Content Reference

M

Target Key

4009