Network Security - Use the Out-of-Band (OOB) interface for all management related traffic

Information

Most Junos OS platforms have a built-in, dedicated out-of-band management interface. It's called fxp0 on high-end routing and security platforms, and me0 or vme on switching platforms. Due to their smaller form factor, J-Series routers and branch SRX devices do not have a dedicated management interface (but any of the built-in Ethernet interfaces can be used for this purpose).

Solution

Configure the chassis dedicated management port for participation on the OOB network. If no dedicate port exists, dedicate an existing network port for management use on the OOB network.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(15)

Plugin: Juniper

Control ID: b0b4f61147fa527e0cbf3edc4ca78a206e2ef11e4300afb24d6049cb79195b73