Physical Security - Diagnostic Ports - Password protect Diagnostic ports - pic-console

Information

Some hardware modules, such as the System Control Board (SCB), System and Switch Board (SSB), Switching and Forwarding Module (SFM), and Forwarding Engine Board (FEB), have a special port that can be used for advanced diagnostics. By default, diagnostic ports are not secured by a password, which makes it possible for an unauthorized user with physical access to the device to gain access to the system and possibly obtain sensitive network specific information.

Solution

Configure a secure password on the PIC console port.

user@host# edit system pic-console-authentication
user@host# set encrypted-password <PASSWORD>

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Juniper

Control ID: 6ab029aadbd48ed974af44710f80dfac88f55d7c149a736fa745a36c2aba8946