Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asia Region
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

This Week: Hardening Junos Devices

Junos Fundamentals
This Week: Hardening Junos Devices
 
Configuring Junos Policies and Firewall Filters
 
Deploying Basic QoS
 
Junos Tips, Techniques, and Templates 2011
 
Securing the Routing Engine on M, MX, and T Series
 
Exploring the Junos CLI
 
Configuring Junos Basics
 
Monitoring and Troubleshooting
 
 

Need Help?

  • Learn How to Buy
  • Call Us
  • Email Us
Print
This Week: Hardening Junos Devices

BOOK DESCRIPTION

Juniper Networks takes the security of its products very seriously and has created proven processes and procedures following industry best practices. This Week: Hardening Junos Devices divides Juniper’s hardening procedures into four topic areas – Non-Technical, Physical Security, Operating System Security, and Configuration Hardening – and delves into sample strategies, example configurations, and dozens of suggestions and useful tips for each.

Encyclopedic in its coverage, This Week: Hardening Junos Devices is simply a book you cannot afford not to read. The author’s 15 years of experience supporting U.S. Government agencies makes this book applicable to high security environments such as service providers, financial institutions, government, and enterprise networks.

"The best network design will not help you if you forget to thoroughly secure and harden your network devices. This book is particularly welcomed by those taking their first steps into the Junos world - it helps map concepts from Cisco IOS into various Junos dialects as well as covers all the bits and pieces you might never even consider, like securing the LCD menu.
- Ivan Pepelnjak, Chief Technology Advisor, NIL Data Communications CCIE 1354 Emeritus, Independent Blogger (ipSpace.net)

 

 

Download Book

Day One books are a free download for our J-Net members*. If you're not a J-Net member, create a user account now. It's fast and there's no commitment or spam. Once you're a member you can come back and download any of the Day One books.


* If you have an existing Juniper user account, you can use it to login to J-Net

ABOUT THE AUTHOR(S)

John Weidley is a Resident Engineer with Juniper Networks. He is certified in Juniper Networks as JNCIS-SEC, JNCIS-SSL, JNCIA-FWV, and JNCIA-EX, and has worked closely supporting U.S. Government agencies for the last 15 years.

 What got you started on this book?

There are hardening guides for other operating systems and a Junos hardening guide is long overdue. Over the years there have been many useful security features developed and built in to Junos but, unfortunately, they are not documented in one single place. This book brings them all together which should be a real time saver.

 Who is this book for?

Network Auditors, Security Engineers, and Network Engineers will all be able to get something from this book. Security books usually go into a lot of detail about policy and theory, so sometimes non-security engineers become uninterested and stop reading. There is some discussion about security policy in the beginning of the book but it's short, to the point, and provides a good foundation. I tried to write this book from a Network Engineer’s perspective with enough security related detail to provide meaningful context.

 After reading this book, what's the take away?

I guess the biggest take away from the book is every organization has unique security requirements and Junos software has many features that can be used to help you meet those requirements. With this book I didn’t want to make general statements like “if you don’t enable this feature, your device will be insecure”. I tried to introduce a topic, provide a brief introduction, identify possible risks, and present possible solutions. Ultimately, it's up to you and your peers to choose the features that will meet your company’s security policy.

 What are you hoping that people will learn from this book?

I hope that readers see the benefits of a single OS and the inherent security features built into Junos. I also hope they see how it is possible to secure their Junos devices while still maintaining operational functionality.

 What do you recommend as the next item to read after this book?

This book does not provide in-depth background information about features or provide commands to verify proper operation. It introduces scenarios and options to enhance the security of the device. I would recommend reading the references in the book to provide additional context. To name a few:

  • Junos Cookbook - Provides solid background information and commands to verify proper operations of specific features.
  • Junos High Availability - Provides a practical operational approach on many topics that contribute to a highly available network, to include SNMP planning, Out-of-band management, scripting and introduces device and network based security.
  • Doug Hank’s Day One guide on Securing the Routing Engine. Although this book takes a different overall approach to writing firewall filters it does provide a lot of foundation and reference information.
 What's your inspiration?

I am a Resident Engineer, which means I am onsite with my customer every day. I’m frequently asked if there is a Hardening guide for Junos or if I could translate other vendor security hardening commands to Junos. There is a definite need for a hardening Junos guide and I was happy to share what I know to give back to the Junos community.

 What's your favorite bit/part in the book?

My favorite part of the book would probably be the physical security section. It may not be as glamorous as the Network security portions but I would say that they are the least explored. Engineers sometimes avoid the features in this section because they think it could negatively impact operations and/or recovery. I hope that this chapter provides enough information so engineers won’t be so apprehensive about using them.

 
 

Blogs

  • Architecting the Network for the IPv6 transition

Recommended Reading

  • IPv6 Innovation
  • Junos for Dummies

Release Highlights

  • Junos Release
 
 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
  • Follow Us
  • j-net
  • YouTube
  • Twitter
  • Facebook
  • RSS
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.

Enterprise

Service Provider

Public Sector

Business Needs 

  • Application Infrastructure
  • Business Continuity
  • Mobility
  • Network Infrastructure
  • Security and Compliance

Locations / Architectures 

  • Campus & Branch
  • Cloud-Ready Data Center
  • Remote & Mobile Users

Industries 

  • Energy and Utilities
  • Financial Services
  • Government
  • Healthcare
  • Education

The Innovators 

  • Customer Stories

Business Needs 

  • Managed Service Provider
  • Network Infrastructure
  • Network Security
  • Network and Service Management
  • Residential
  • Telepresence

Locations / Architectures 

  • Core
  • Packet Transport
  • Cloud-Ready Data Center
  • Universal Access
  • Universal Edge

Segments 

  • Cable Operator
  • Wireline Carrier
  • Content Service Provider
  • Wireless Carrier

Business Needs 

  • Application Infrastructure
  • Disaster Recovery / Business Continuity
  • Security and Compliance
  • Certifications

Locations / Architectures 

  • Branch Office
  • Campus
  • Cloud-Ready Data Center
  • Remote Users
  • VPNs and WAN

Products by Category

  • Application Acceleration
  • Content and Media Delivery
  • Data Center Fabric
  • Identity and Policy Control
  • Juniper Developer Network
  • Mobile Infrastructure
  • Network Management
  • Network Operating System
  • Packet Transport
  • Routing
  • Security
  • Software
  • Switching
  • Time Synchronization
  • Wireless
  • End-of-Sale Products

Services

  • Consulting Services
  • Installation and Configuration Services
  • Technical Services

All Products & Services

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

About Juniper

News and Information

The Juniper Difference

  • Company Profile
  • Leadership
  • Business Partners
  • Careers
  • Contact Us
  • Analyst Relations
  • Press Center
  • Events
  • Subscriptions
  • Innovations
  • Awards
  • Recognition
  • Case Studies and Customer Quotes
  • Corporate Responsibility
  • Ventures
Help
|
My Account
|
Log Out