3.3 Ensure unused interfaces are set to disable

Information

Unused interfaces should be explicitly disabled.

Rationale:
JUNOS routers can be installed with tens or even hundreds of physical interfaces of different types. To ensure that unused interfaces are not connected to networks, either accidently or by a malicious user seeking to bypass security measures, all unused interfaces should be explicitly disabled.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To disable an interface enter the following command from the [edit interfaces <interface name>] hierarchy.
[edit interfaces <interface name>]
user@host#set disable

Default Value:
Installed physical interfaces are enabled by default on most platforms.

See Also

https://workbench.cisecurity.org/files/2278

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|9.2

Plugin: Juniper

Control ID: 3872fd9f89e75ef7154c8be7df690fd2330db76c07703c0b4dfccec4becbe6b7