6.10.1.1 Ensure SSH Service is Configured if Remote CLI is Required

Information

SSH should be utilized for remote console sessions to Juniper routers.

Rationale:

SSH provides administrators with a remote console session on the router in a similar fashion to Telnet. Unlike Telnet, SSH encrypts all data as it transits the network and ensures the identity of the remote host.

Because of this extra protection, all remote console sessions should use SSH.

If Remote CLI or services which use SSH for transport, like Secure Copy (SCP) or NETCONF, are required SSH should be disabled.

Impact:

Disabling SSH may result in loss of remote management of the device and also impact other services, like NETCONF, which use SSH for transport.

Solution

To enable SSH access issue the following command from the [edit system] hierarchy:

[edit system]
user@host#set services ssh

Where SSH is used, all other Recommendations in this section should be considered.
If SSH is currently configured but is not required it should be disabled using the following command from the [edit system] hierarchy:

[edit system]
user@host#delete services ssh

Default Value:

For most platforms SSH access is enabled by default.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), CSCv7|11.5

Plugin: Juniper

Control ID: b3fd41e22d314c508ee59e5d532455458c59d62daf22f19bd26290724a5e4c2c