SV-214696r385498_rule
V-214696
SRG-NET-000147
JUSX-VN-000031
CAT II
10
Remove the no-anti-replay Internet Key Exchange (IKE) option from the VPN configuration. By default the SRX has a replay window of 64 or 32, depending on the platform.
Example:
[edit]
delete security vpn name ike no-anti-replay
Verify anti-replay service is enabled.
[edit]
show security ipsec security-associations index 16384 detail
If anti-replay service is not enabled, this is a finding.
V-214696
False
JUSX-VN-000031
Verify anti-replay service is enabled.
[edit]
show security ipsec security-associations index 16384 detail
If anti-replay service is not enabled, this is a finding.
M
4009