Check: JUSX-DM-000030
Juniper SRX Services Gateway NDM STIG:
JUSX-DM-000030
(in versions v3 r3 through v3 r2)
Title
For local accounts created on the device, the Juniper SRX Services Gateway must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. (Cat III impact)
Discussion
By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. Juniper SRX is unable to comply with the 15-minute time period part of this control.
Check Content
Verify the number of unsuccessful logon attempts is set to 3. [edit] show system login retry-options If the number of unsuccessful logon attempts is not set to 3, this is a finding.
Fix Text
Configure the number of unsuccessful logon attempts for all login account, globally. [edit] set system login retry-options tries-before-disconnect 3
Additional Identifiers
Rule ID: SV-223188r1018645_rule
Vulnerability ID: V-223188
Group Title: SRG-APP-000065-NDM-000214
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-000044 |
Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period. |
Controls
| Number | Title |
|---|---|
| AC-7 |
Unsuccessful Logon Attempts |