STIGQter STIGQter: STIG Summary: Juniper SRX Services Gateway VPN Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The Juniper SRX Services Gateway VPN must specify Perfect Forward Secrecy (PFS).

DISA Rule

SV-214680r385561_rule

Vulnerability Number

V-214680

Group Title

SRG-NET-000512

Rule Version

JUSX-VN-000013

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN gateway to ensure PFS is enabled. The following commands configure an IPsec policy, enabling PFS using Diffie-Hellman group 14 and associates the IPsec proposal configured in the previous example.

[edit]
set security ipsec policy <IPSEC-POLICY> perfect-forward-secrecy keys group14
set security ipsec policy <IPSEC-POLICY> proposals <IPSEC-PROPOSAL>

Check Contents

Examine all IPsec profiles to verify PFS is enabled.

[edit]
show security ipsec policy

If PFS is not configured, this is a finding.

Vulnerability Number

V-214680

Documentable

False

Rule Version

JUSX-VN-000013

Severity Override Guidance

Examine all IPsec profiles to verify PFS is enabled.

[edit]
show security ipsec policy

If PFS is not configured, this is a finding.

Check Content Reference

M

Target Key

4009

Comments