STIGQter STIGQter: STIG Summary:

Juniper SRX Services Gateway VPN Security Technical Implementation Guide

Version: 3

Release: 2 Benchmark Date: 30 Jan 2025

CheckedNameTitle
☐SV-214668r997551_ruleThe Juniper SRX Services Gateway VPN must limit the number of concurrent sessions for user accounts to one (1) and administrative accounts to three (3), or set to an organization-defined number.
☐SV-214669r856572_ruleThe Juniper SRX Services Gateway VPN must renegotiate the IPsec security association after 8 hours or less.
☐SV-214670r856574_ruleThe Juniper SRX Services Gateway VPN must renegotiate the IKE security association after 24 hours or less.
☐SV-214671r382780_ruleThe Juniper SRX Services Gateway VPN device also fulfills the role of IDPS in the architecture, the device must inspect the VPN traffic in compliance with DoD IDPS requirements.
☐SV-214672r1056079_ruleThe Juniper SRX Services Gateway VPN must use AES256 for the IPsec proposal to protect the confidentiality of remote access sessions.
☐SV-214673r1056082_ruleThe Juniper SRX Services Gateway VPN must use AES256 encryption for the Internet Key Exchange (IKE) proposal to protect the confidentiality of remote access sessions.
☐SV-214674r1056179_ruleThe Juniper SRX Services Gateway VPN must be configured to use Diffie-Hellman (DH) group 15 or higher.
☐SV-214675r1056088_ruleThe Juniper SRX Services Gateway VPN must be configured to use IPsec with SHA256 or greater to negotiate hashing to protect the integrity of remote access sessions.
☐SV-214676r382735_ruleThe Juniper SRX Services Gateway VPN must ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies.
☐SV-214677r385561_ruleThe Juniper SRX Services Gateway VPN must use Internet Key Exchange (IKE) for IPsec VPN Security Associations (SAs).
☐SV-214678r864169_ruleIf IDPS inspection is performed separately from the Juniper SRX Services Gateway VPN device, the VPN must route sessions to an IDPS for inspection.
☐SV-214679r385561_ruleThe Juniper SRX Services Gateway VPN must not accept certificates that have been revoked when using PKI for authentication.
☐SV-214680r385561_ruleThe Juniper SRX Services Gateway VPN must specify Perfect Forward Secrecy (PFS).
☐SV-214681r385561_ruleThe Juniper SRX Services Gateway VPN must use Encapsulating Security Payload (ESP) in tunnel mode.
☐SV-214682r382903_ruleThe Juniper SRX Services Gateway must disable or remove unnecessary network services and functions that are not used as part of its role in the architecture.
☐SV-214683r997555_ruleThe Juniper SRX Services Gateway VPN must use IKEv2 for IPsec VPN security associations.
☐SV-214684r385486_ruleThe Juniper SRX Services Gateway VPN must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
☐SV-214685r385489_ruleThe Juniper SRX Services Gateway VPN must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
☐SV-214686r954210_ruleThe Juniper SRX Services Gateway VPN must use multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts.
☐SV-214688r385519_ruleThe Juniper SRX Services Gateway VPN must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
☐SV-214689r1056184_ruleThe Juniper SRX Services Gateway VPN must terminate all network connections associated with a communications session at the end of the session.
☐SV-214690r1056094_ruleThe Juniper SRX Services Gateway VPN Internet Key Exchange (IKE) must be configured to use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network.
☐SV-214691r1056097_ruleThe Juniper SRX Services Gateway VPN IKE must use NIST FIPS-validated cryptography to implement encryption services for unclassified VPN traffic.
☐SV-214692r383107_ruleThe Juniper SRX Services Gateway VPN must configure Internet Key Exchange (IKE) with SHA1 or greater to protect the authenticity of communications sessions.
☐SV-214693r856577_ruleThe Juniper SRX Services Gateway VPN must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions.
☐SV-214694r856578_ruleThe Juniper SRX Services Gateway VPN must only allow incoming VPN communications from organization-defined authorized sources routed to organization-defined authorized destinations.
☐SV-214695r856579_ruleThe Juniper SRX Services Gateway VPN must disable split-tunneling for remote clients VPNs.
☐SV-214696r1015749_ruleThe Juniper SRX Services Gateway VPN must use anti-replay mechanisms for security associations.