STIGQter STIGQter: STIG Summary: Juniper EX Series Switches Network Device Management Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Juniper EX switch must be configured to generate audit records when successful/unsuccessful logon attempts occur.

DISA Rule

SV-253933r961824_rule

Vulnerability Number

V-253933

Group Title

SRG-APP-000503-NDM-000320

Rule Version

JUEX-NM-000560

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the network device to generate audit records when successful/unsuccessful logon attempts occur.

set system syslog file <file name> any info
set system syslog file <file name> structured-data << (Optional) Only if structured data format is required
set system syslog host <external syslog address> authorization info
set system syslog host <external syslog address> structured-data << (Optional) Only if structured data format is required
set system syslog time-format <(year|millisecond)>

Check Contents

Determine if the network device generates audit records when successful/unsuccessful logon attempts occur.

Junos logs all logon attempts via the "authorization" syslog facility (or facility "any"). Verify logging level "any info" or "authorization info" is configured.

[edit system syslog]
file <file name> {
authorization info;
}
host <external syslog address> {
any info;
}
time-format year millisecond;
Syslog outputs in standard format unless the "structured-data" directive is configured. Verify the "structured-data" command for all files and external syslog servers requiring that format. For example:

[edit system syslog]
host <syslog address> {
authorization info;
structured-data;
}
file <file name> {
any info;
structured-data;
}

If it does not generate audit records when successful/unsuccessful logon attempts occur, this is a finding.

Vulnerability Number

V-253933

Documentable

False

Rule Version

JUEX-NM-000560

Severity Override Guidance

Determine if the network device generates audit records when successful/unsuccessful logon attempts occur.

Junos logs all logon attempts via the "authorization" syslog facility (or facility "any"). Verify logging level "any info" or "authorization info" is configured.

[edit system syslog]
file <file name> {
authorization info;
}
host <external syslog address> {
any info;
}
time-format year millisecond;
Syslog outputs in standard format unless the "structured-data" directive is configured. Verify the "structured-data" command for all files and external syslog servers requiring that format. For example:

[edit system syslog]
host <syslog address> {
authorization info;
structured-data;
}
file <file name> {
any info;
structured-data;
}

If it does not generate audit records when successful/unsuccessful logon attempts occur, this is a finding.

Check Content Reference

M

Target Key

5477