STIGQter STIGQter: STIG Summary: Juniper SRX SG NDM Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The Juniper SRX Services Gateway must ensure TCP forwarding is disabled for SSH to prevent unauthorized access.

DISA Rule

SV-223214r513331_rule

Vulnerability Number

V-223214

Group Title

SRG-APP-000142-NDM-000245

Rule Version

JUSX-DM-000114

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the configuration mode, enter the following commands to disable TCP forwarding for the SSH protocol.

[edit]
set system services ssh no-tcp-forwarding

Check Contents

Use the CLI to view this setting for disabled for SSH.

[edit]
show system services ssh

If TCP forwarding is not disabled for the root user, this is a finding.

Vulnerability Number

V-223214

Documentable

False

Rule Version

JUSX-DM-000114

Severity Override Guidance

Use the CLI to view this setting for disabled for SSH.

[edit]
show system services ssh

If TCP forwarding is not disabled for the root user, this is a finding.

Check Content Reference

M

Target Key

4098

Comments