SV-253998r844027_rule
V-253998
SRG-NET-000078-RTR-000001
JUEX-RT-000260
CAT III
10
Configure interface firewall filters to log all deny statements.
All discarding firewall filter terms:
<filter terms and match conditions>
set firewall family inet filter <filter name> term <name> then log
set firewall family inet filter <filter name> term <name> then syslog <<< Minimally must be configured for all discarding filter terms.
set firewall family inet filter <filter name> term <name> then discard
<filter terms and match conditions>
set firewall family inet6 filter <filter name> term <name> then log
set firewall family inet6 filter <filter name> term <name> then syslog <<< Minimally must be configured for all discarding filter terms.
set firewall family inet6 filter <filter name> term <name> then discard
Review the router interface firewall filters to verify all deny statements are logged. At a minimum, all discarding filter terms must have the "syslog" action enabled.
Verify all discarding firewall filter terms are configured with (minimally) the "syslog" action:
[edit firewall]
family inet {
filter <filter name> {
term <name> {
from {
<match conditions>;
}
then {
log;
syslog; <<< Must be enabled for local and external syslog.
discard;
}
}
}
}
family inet6 {
filter <filter name> {
term <name> {
from {
<match conditions>;
}
then {
log;
syslog; <<< Must be enabled for local and external syslog.
discard;
}
}
}
}
If packets being dropped are not logged, this is a finding.
V-253998
False
JUEX-RT-000260
Review the router interface firewall filters to verify all deny statements are logged. At a minimum, all discarding filter terms must have the "syslog" action enabled.
Verify all discarding firewall filter terms are configured with (minimally) the "syslog" action:
[edit firewall]
family inet {
filter <filter name> {
term <name> {
from {
<match conditions>;
}
then {
log;
syslog; <<< Must be enabled for local and external syslog.
discard;
}
}
}
}
family inet6 {
filter <filter name> {
term <name> {
from {
<match conditions>;
}
then {
log;
syslog; <<< Must be enabled for local and external syslog.
discard;
}
}
}
}
If packets being dropped are not logged, this is a finding.
M
5479