STIGQter STIGQter: STIG Summary:

Juniper SRX Services Gateway VPN Security Technical Implementation Guide

Version: 3

Release: 2 Benchmark Date: 30 Jan 2025

CheckedNameTitle
SV-214668r997551_ruleThe Juniper SRX Services Gateway VPN must limit the number of concurrent sessions for user accounts to one (1) and administrative accounts to three (3), or set to an organization-defined number.
SV-214669r856572_ruleThe Juniper SRX Services Gateway VPN must renegotiate the IPsec security association after 8 hours or less.
SV-214670r856574_ruleThe Juniper SRX Services Gateway VPN must renegotiate the IKE security association after 24 hours or less.
SV-214671r382780_ruleThe Juniper SRX Services Gateway VPN device also fulfills the role of IDPS in the architecture, the device must inspect the VPN traffic in compliance with DoD IDPS requirements.
SV-214672r1056079_ruleThe Juniper SRX Services Gateway VPN must use AES256 for the IPsec proposal to protect the confidentiality of remote access sessions.
SV-214673r1056082_ruleThe Juniper SRX Services Gateway VPN must use AES256 encryption for the Internet Key Exchange (IKE) proposal to protect the confidentiality of remote access sessions.
SV-214674r1056179_ruleThe Juniper SRX Services Gateway VPN must be configured to use Diffie-Hellman (DH) group 15 or higher.
SV-214675r1056088_ruleThe Juniper SRX Services Gateway VPN must be configured to use IPsec with SHA256 or greater to negotiate hashing to protect the integrity of remote access sessions.
SV-214676r382735_ruleThe Juniper SRX Services Gateway VPN must ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies.
SV-214677r385561_ruleThe Juniper SRX Services Gateway VPN must use Internet Key Exchange (IKE) for IPsec VPN Security Associations (SAs).
SV-214678r864169_ruleIf IDPS inspection is performed separately from the Juniper SRX Services Gateway VPN device, the VPN must route sessions to an IDPS for inspection.
SV-214679r385561_ruleThe Juniper SRX Services Gateway VPN must not accept certificates that have been revoked when using PKI for authentication.
SV-214680r385561_ruleThe Juniper SRX Services Gateway VPN must specify Perfect Forward Secrecy (PFS).
SV-214681r385561_ruleThe Juniper SRX Services Gateway VPN must use Encapsulating Security Payload (ESP) in tunnel mode.
SV-214682r382903_ruleThe Juniper SRX Services Gateway must disable or remove unnecessary network services and functions that are not used as part of its role in the architecture.
SV-214683r997555_ruleThe Juniper SRX Services Gateway VPN must use IKEv2 for IPsec VPN security associations.
SV-214684r385486_ruleThe Juniper SRX Services Gateway VPN must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-214685r385489_ruleThe Juniper SRX Services Gateway VPN must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-214686r954210_ruleThe Juniper SRX Services Gateway VPN must use multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts.
SV-214688r385519_ruleThe Juniper SRX Services Gateway VPN must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
SV-214689r1056184_ruleThe Juniper SRX Services Gateway VPN must terminate all network connections associated with a communications session at the end of the session.
SV-214690r1056094_ruleThe Juniper SRX Services Gateway VPN Internet Key Exchange (IKE) must be configured to use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network.
SV-214691r1056097_ruleThe Juniper SRX Services Gateway VPN IKE must use NIST FIPS-validated cryptography to implement encryption services for unclassified VPN traffic.
SV-214692r383107_ruleThe Juniper SRX Services Gateway VPN must configure Internet Key Exchange (IKE) with SHA1 or greater to protect the authenticity of communications sessions.
SV-214693r856577_ruleThe Juniper SRX Services Gateway VPN must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions.
SV-214694r856578_ruleThe Juniper SRX Services Gateway VPN must only allow incoming VPN communications from organization-defined authorized sources routed to organization-defined authorized destinations.
SV-214695r856579_ruleThe Juniper SRX Services Gateway VPN must disable split-tunneling for remote clients VPNs.
SV-214696r1015749_ruleThe Juniper SRX Services Gateway VPN must use anti-replay mechanisms for security associations.