6.11.3 Ensure Console Port is Set to Disabled

Information

The JUNOS Device's Console Port should be disabled.

Rationale:

Administrators often use Console Port on a JUNOS Device to configure the Device via the CLI when they have physical access to the device.

In high security environments or deployments where the physical security of the JUNOS Device cannot be assured, such as CPE (Customer Premises Equipment), Point of Sales (POS) or Branch Office installations, disabling the console port will increase the difficulty of accessing the router for an attacker with physical access.

Connecting to the console will not allow access to the CLI without restarting the JUNOS Device to access recovery options, an event which will show up in your monitoring and audit logs.

Impact:

The JUNOS Device's CLI will no longer be accessible through the Console Port without rebooting the device.

Solution

To disable the Console Port, issue the following command from the [edit system ports] hierarchy;

[edit system ports]
user@host#set console disabled

Default Value:

By default, the Console Port is enabled

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: 112ebe93aa410497d7c9428369f0c0f8e06dc6d6d6dbf76a67499c8a0996eeb9