The Juniper SRX Services Gateway must terminate a device management session after 10 minutes of inactivity, except to fulfill documented and validated mission requirements.
From Juniper SRX SG NDM Security Technical Implementation Guide
Part of SRG-APP-000190-NDM-000267
Associated with:
CCI-001133
SV-81027r1_rule
The Juniper SRX Services Gateway must terminate a device management session after 10 minutes of inactivity, except to fulfill documented and validated mission requirements.
Vulnerability discussion
Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session. Quickly terminating an idle session also frees up resources. This requirement does not mean that the device terminates all sessions or network access; it only ends the inactive session.User accounts, including the account of last resort must be assigned to a login class. Configure all login classes with an idle timeout value. Pre-defined classes do not support configurations, therefore should not be used for DoD implementations. The root account cannot be assigned to a login-class which is why it is critical that this account be secured in accordance with DoD policy.
Check content
Verify idle-timeout is set for 10 minutes.
[edit]
show system login
If a timeout value of 10 or less is not set for each class, this is a finding.
Fix text
Configure all login classes with an idle timeout value.
[edit]
set system login-class idle-timeout 10
All users must be set to a login-class; however, to ensure that the CLI is set to a default timeout value, enter the following in operational mode:
set cli idle-timeout 10
Pro Tips
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer