SV-214532r557389_rule
V-214532
SRG-NET-000192-ALG-000121
JUSX-AG-000124
CAT II
10
To enable screen protection, the screen profile must be associated with individual security zones using the following command. Recommend assigning "untrust-screen" profile name.
Apply screen to each outbound interface example:
set security zones security-zone untrust interfaces <OUTBOUND-INTERFACE>
set security zones security-zone trust screen untrust-screen
Obtain and review the list of outbound interfaces and zones. This is usually part of the System Design Specification or Accreditation Package.
Review each of the configured outbound interfaces and zones. Verify zones that communicate outbound have been configured with DoS screens.
[edit]
show security zones <security-zone-name>
If the zone for the security screen has not been applied to all outbound interfaces, this is a finding.
V-214532
False
JUSX-AG-000124
Obtain and review the list of outbound interfaces and zones. This is usually part of the System Design Specification or Accreditation Package.
Review each of the configured outbound interfaces and zones. Verify zones that communicate outbound have been configured with DoS screens.
[edit]
show security zones <security-zone-name>
If the zone for the security screen has not been applied to all outbound interfaces, this is a finding.
M
4004