STIGQter STIGQter: STIG Summary: Juniper EX Series Switches Network Device Management Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Juniper EX switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

DISA Rule

SV-253900r1043177_rule

Vulnerability Number

V-253900

Group Title

SRG-APP-000142-NDM-000245

Rule Version

JUEX-NM-000230

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the network device to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

delete system services ftp
delete system services telnet
delete system services web-management

Note: Delete other configured but unnecessary system services.

Check Contents

Determine if the network device prohibits the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

Verify unnecessary or nonsecure functions are not configured or are explicitly disabled. For example, FTP and Telnet are nonsecure. Verify these services are not enabled as in the example below:
[edit system services]
ftp;
telnet;

If any unnecessary or nonsecure functions are permitted, this is a finding.

Vulnerability Number

V-253900

Documentable

False

Rule Version

JUEX-NM-000230

Severity Override Guidance

Determine if the network device prohibits the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

Verify unnecessary or nonsecure functions are not configured or are explicitly disabled. For example, FTP and Telnet are nonsecure. Verify these services are not enabled as in the example below:
[edit system services]
ftp;
telnet;

If any unnecessary or nonsecure functions are permitted, this is a finding.

Check Content Reference

M

Target Key

5477