Firewall Filter - Ensure the last term, default-deny, includes the syslog option

Information

Finally, configure the default deny term to discard and log all traffic. The log option saves the packet header information in a buffer on the Packet Forwarding Engine (PFE) and the syslog option stores the packet header information on the Routing Engine.

Solution

Configure the firewall engine to log denied traffic.

user@host# edit firewall family inet filter <NAME>
user@host# set term default-deny then syslog

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5)

Plugin: Juniper

Control ID: 98d507ed6ce8dfaf93c1c99a35a347ba8abbd415e086a5d067fd4f46ddbb95be