SV-229025r518253_rule
V-229025
SRG-APP-000516-NDM-000317
JUSX-DM-000097
CAT I
10
Configure the Juniper SRX to forward logon requests to a RADIUS or TACACS+. Remove local users configured on the device (CCI-000213) so the AAA server cannot default to using a local account.
[edit]
set system tacplus-server address <server ipaddress> port 1812 secret <shared secret>
or
[edit]
set system radius-server address <server ipaddress> port 1812 secret <shared secret>
Note: DoD policy is that redundant AAA servers are required to mitigate the risk of a failure of the primary AAA device.
Verify the Juniper SRX is configured to forward logon requests to a RADIUS or TACACS+.
From the CLI operational mode enter:
show system radius-server
or
show system tacplus-server
If the Juniper SRX is not configured to use at least one RADIUS or TACACS+ server, this is a finding.
V-229025
False
JUSX-DM-000097
Verify the Juniper SRX is configured to forward logon requests to a RADIUS or TACACS+.
From the CLI operational mode enter:
show system radius-server
or
show system tacplus-server
If the Juniper SRX is not configured to use at least one RADIUS or TACACS+ server, this is a finding.
M
4098