Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-66537 | JUSX-DM-000156 | SV-81027r1_rule | Medium |
Description |
---|
Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session. Quickly terminating an idle session also frees up resources. This requirement does not mean that the device terminates all sessions or network access; it only ends the inactive session. User accounts, including the account of last resort must be assigned to a login class. Configure all login classes with an idle timeout value. Pre-defined classes do not support configurations, therefore should not be used for DoD implementations. The root account cannot be assigned to a login-class which is why it is critical that this account be secured in accordance with DoD policy. |
STIG | Date |
---|---|
Juniper SRX SG NDM Security Technical Implementation Guide | 2019-06-28 |
Check Text ( C-67183r1_chk ) |
---|
Verify idle-timeout is set for 10 minutes. [edit] show system login If a timeout value of 10 or less is not set for each class, this is a finding. |
Fix Text (F-72613r1_fix) |
---|
Configure all login classes with an idle timeout value. [edit] set system login-class All users must be set to a login-class; however, to ensure that the CLI is set to a default timeout value, enter the following in operational mode: set cli idle-timeout 10 |