Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Event Logging Overview

The evaluated configuration requires the auditing of configuration changes through the system log. The device generates audit log entries for all auditable events on the device.

In addition, Junos OS can:

  • Send automated responses to audit events (syslog entry creation).

  • Allow authorized managers to examine audit logs.

  • Send audit files to external servers.

  • Allow authorized managers to return the system to a known state.

The logging specific for the Security Functional Requirements fulfilled by the device in the evaluated configuration captures the events. For each event, the TOE captures the date and time of the event, the type of the event, the subject identity (if applicable), and the outcome (success or failure) of the event.

For each audit event type, based on the auditable event definitions of the functional components included in the Security Target, the additional data listed below for each SFR is also captured.

Table 1 shows sample for syslog auditing for CPP_ND_v3.0e.

Table 1: Auditable Events

Requirement

Auditable Events and Data

FAU_GEN.1

No additional events or audit record content

FAU_GEN.1/VPN

No additional events or audit record content

FAU_GEN.2

No additional events or audit record content

FAU_STG_EXT.1

Configuration of local audit settings.

Jun 30 12:15:03 router1 mgd[4321]: UI_CMDLINE_READ_LINE: User 'root', command 'set system syslog file Audit-File authorization info'

FCS_CKM.1

No additional events or audit record content

FCS_CKM.1/IKE

No additional events or audit record content

FCS_CKM.2

No additional events or audit record content

FCS_CKM.4

No additional events or audit record content

FCS_COP.1/ DataEncryption

No additional events or audit record content

FCS_COP.1/SigGen

No additional events or audit record content

FCS_COP.1/Hash

No additional events or audit record content

FCS_COP.1/ KeyedHash

No additional events or audit record content

FCS_IPSEC_EXT.1

The TOE stores the session establishment with peer, including the entire packet contents of the packets transmitted and received during the session establishment: user@host:fips# run show log iked | no-more | grep vpn Jun 14 10:40:49.291712 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ipsec-sa selection successful for spi (0x8a45e874) local-ip (20.1.1.1) remote-ip (20.1.1.2) vpn (IPSEC_VPN)

user@host:fips# run show log iked | no-more | grep success Jun 14 10:40:49.278061 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ike-atec-dh-generate successful response received for ipcindex=45109,local-ip=none,remote-ip=none Jun 14 10:40:49.290742 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] atec-validate-migrate for ed (0x2c09028) success in remote id validation Jun 14 10:40:49.291392 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] TSi: traffic-selectormatch for ts-match Successful,C:ipv4(0.0.0.0-255.255.255.255) R:ipv4(10.1.1.0-10.1.1.255) N:ipv4(10.1.1.0-10.1.1.255) Jun 14 10:40:49.291656 [EXT] [TUNL] [20.1.1.1 <-> 20.1.1.2] ike_tunnel_anchor_node_tunnel_add: Anchor tunnel add for tunnel 500009: success total tunnel adds:9 Jun 14 10:40:49.291682 [DET] [TUNL] [20.1.1.1 <-> 20.1.1.2] tunnel-sadb-add success with local-spi (0x8a45e874) Jun 14 10:40:49.291712 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ipsec-sa selection successful for spi (0x8a45e874) local-ip (20.1.1.1) remote-ip (20.1.1.2) vpn (IPSEC_VPN) Jun 14 10:40:49.292404 [TER] [PEER] [20.1.1.1 <-> 20.1.1.2] IKE: Gateway N:IKE_GW L:20.1.1.1:500 R:20.1.1.2:500 Successful ike-id:20.1.1.2 U:N/A IKE:IKEv2 Role:R Jun 14 10:40:49.294256 [DET] [DIST] [20.1.1.1 <-> 20.1.1.2] ike_dist_ipsec_tunnel_info_add: IPsec distribution tunnel info add to db successful Tunnel Id:500009 Client Id:20 Instance:0 Jun 14 10:40:49.295072 [EXT] [IPSC] [20.1.1.1 <-> 20.1.1.2] ipsec_common_msg_send: Successfully sent IPC msg tag 4 from iked to SPU.0.20 Jun 14 10:40:49.295292 [EXT] [IPSC] [20.1.1.1 <-> 20.1.1.2] ipsec_common_msg_send: Successfully sent IPC msg tag 4 from iked to SPU.0.21 Jun 14 10:40:49.296004 [DET] [STER] [20.1.1.1 <-> 20.1.1.2] Successfully modified st0 next hop meta data for tunnel 500009 Jun 14 10:40:49.297336 [EXT] [IPSC] [20.1.1.1 <-> 20.1.1.2] ipsec_common_msg_send: Successfully sent IPC msg tag 4 from iked to SPU.0.20 Jun 14 10:42:24.328902 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ike-atec-dh-generate successful response received for ipcindex= 45111,local-ip=none,remote-ip=none Jun 14 10:42:24.332381 [DET] [ATEC]

[20.1.1.1 <-> 20.1.1.2] ike-atec-dh-compute successful response received for ipc-index=0 Jun 14 10:42:24.333295 [DET] [PUBL] [20.1.1.1 <-> 20.1.1.2] publish-ike-sa successful for ike-sa-index 11282 ike-sa 0x21dec24 Jun 14 10:42:29.316880 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] TSi: traffic-selectormatch for ts-match Successful,C:ipv4(0.0.0.0-255.255.255.255) R:ipv4(10.1.1.0-10.1.1.255) N:ipv4(10.1.1.0-10.1.1.255) Jun 14 10:42:29.316889 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] TSr: traffic-selectormatch for ts-match Successful,C:ipv4(0.0.0.0-255.255.255.255) R:ipv4(30.1.1.0-30.1.1.255) N:ipv4(30.1.1.0-30.1.1.255) Jun 14 10:42:29.317147 [DET] [TUNL] [20.1.1.1 <-> 20.1.1.2] tunnel-sadb-add success with local-spi (0x80eeab18) Jun 14 10:42:29.317178 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ipsec-sa selection successful for spi (0x80eeab18) local-ip (20.1.1.1) remote-ip (20.1.1.2) vpn (IPSEC_VPN) Jun 14 10:42:29.320369 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ike-atec-dh-generate successful response received for ipcindex=45113,local-ip=none,remote-ip=none Jun 14 10:42:29.323800 [DET] [ATEC] [20.1.1.1 <-> 20.1.1.2] ike-atec-dh-compute successful response received for ipc-index=0 Jun 14 10:42:29.325513 [EXT] [IPSC] [20.1.1.1 <-> 20.1.1.2] ipsec_common_msg_send: Successfully sent IPC msg tag 4 from iked to SPU.0.20

Failure to Establish SA and Reason for Failure:

<27>1 2022-07-25T07:40:00.019Z host kmd 20805 - - IKE negotiation failed with error: No proposal chosen. IKE Version: 2, VPN: ike-vpn-devices Gateway: gw-b, Local: 10.1.5.129/500, Remote: 10.1.5.29/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0: Role: Initiator <27>1 2022-07-25T07:40:00.020Z host kmd 20805 - - IPSec negotiation failed with error: No proposal chosen. IKE Version: 2, VPN: ike-vpn-devices Gateway: gw-b, Local: 10.1.5.129/500, Remote: 10.1.5.29/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0

FCS_NTP_EXT.1

The TOE captures the configuration of a new time server, and a removal of a configured time server.

The identity of the new or the removed server is stored in the audit log:

<182>1 2023-02-22T14:23:37.828Z host mgd 12129 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.129 username="root" action="set" pathname="[system ntp server 10.1.1.160]" delimiter="" value=""] User 'root' set: [system ntp server 10.1.1.160]

Removal of configured time server and identity:

<182>1 2023-02-22T14:24:54.508Z host mgd 12129 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.129 username="root" action="delete" pathname="[system ntp server 10.1.1.160]" delimiter="" value=""] User 'root' delete: [system ntp server 10.1.1.160]

FCS_RBG_EXT.1

No additional events or audit record content

FCS_SSH_EXT.1

The TOE records each failure to establish an SSH session, including the reason for the failure and the Non-TOE endpoint of attempted connection (IP Address) in the following format: sshd 72404 - - Unable to negotiate with 1.1.1.2 port 42168: no matching cipher found. Their offer: chacha20-poly1305@openssh.com, aes128-ctr,aes192-ctr, aes256-ctr, aes128-gcm@openssh.com, aes256-gcm@openssh.com, aes128-cbc, aes192-cbc, aes256-cbc

For the establishment of a SSH connection, the TOE also records the non-TOE endpoint of connection (IP Address). For the termination of a SSH connection session, the TOE also records the non-TOE endpoint of connection (IP Address).

When dropping of packet(s) outside defined size limits, the TOE also records the packet size:

Jun 01 08:35:14 host sshd[10615]: Bad packet length 516882381. [preauth]

FCS_SSHS_EXT.1

No additional events or audit record content

FDP_RIP.2

No additional events or audit record content

FIA_AFL.1

The TOE captures the meeting or exceeding of the limit for unsuccessful login attempts, and stores additionally the origin (e.g. IP Address) of the origin. The log entry generation function is somewhat complex and is described below:

sshd - SSHD_LOGIN_ATTEMPTS_THRESHOLD: Threshold for unsuccessful authentication attempts (3) reached by user ' security-administrator' Login lockout configuration details: [edit] root@host:fips# run show system login lockout User Lockout start Lockout end security-administrator 2023-01-10 15:03:26 IST 2023-01-10 15:04:26 IST Log for the login lockout configuration: Jan 10 15:03:26 host sshd[63687]: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'security-administrator' has been locked out from logins

Status of the session closed after the lockout period: ssh security-administrator@host Password: Connection closed by 10.209.21.170 port 22 Log for the closed session after lockout period: Jan 10 15:04:10 host sshd[63694]: PAM_USER_LOCK_ACCOUNT_LOCKED: Account for user security-administrator is locked.

Establishes the session through the console as the root user during lockout period: login: security-administrator Password: Last login: Tue Jan 10 15:01:43 on ttyu0 --- JUNOS 24.4R1.9 Kernel 64-bit JNPR-12.1-20220816.a81ed05_buil security-administrator@bm-a:fips> [edit] root@host:fips# run show system users 3:04PM up 4 days, 3:59, 2 users, load averages: 0.28, 0.21, 0.22 USER TTY FROM LOGIN@ IDLE WHAT security-a u0 - 3:03PM - -cli (cli)

Log for the session established through the console as the root user during lockout period: Jan 10 15:03:52 host login[63625]: LOGIN_INFORMATION: User security-administrator logged in from host [unknown] on device ttyu0

Security Administrator may unlock an account that is locked from remote access (e.g. SSH): Thu May 09 15:09:46 [user@ttbgshell011:~] ssh test@nms-mx304-a Password: Password: Password: Received disconnect from 10.209.4.145 port 22:2: Too many password failures for test Disconnected from 10.209.4.145 port 22 Thu May 09 20:01:19 [user@ttbg-shell011:~] [edit] root@host# run show system login lockout User Lockout start Lockout end test 2024-05-09 20:01:04 IST 2024-05-09 20:05:04 IST [edit] root@host# sshd: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'test' has been locked out from logins sshd: PAM_USER_LOCK_LOGIN_REQUESTS_DENIED: Login requests from host '10.220.196.34' are denied sshd: PAM_USER_LOCK_ACCOUNT_LOCKED: Account for user test is locked. [edit] root@host# run show system login lockout User accounts not locked [edit] root@host# run show system uptime Current time: 2024-05-09 20:03:10 IST Time Source: LOCAL CLOCK System booted: 2024-05-07 19:19:44 IST (2d 00:43 ago) Protocols started: 2024-05-07 19:22:16 IST (2d 00:40 ago) Last configured: 2024-05-09 20:00:29 IST (00:02:41 ago) by root 8:03PM up 2 days, 43 mins, 1 users, load averages: 0.21, 0.15, 0.10 [edit] root@host# mgd[78360]: LIBJNX_LOGIN_ACCOUNT_UNLOCKED: Account for user 'test' has been unlocked for logins

FIA_PMG_EXT.1

No additional events or audit record content

FIA_UIA_EXT.1

The TOE captures each use of identification and authentication mechanisms, and stores in the audit record the identity of the user and the origin of the attempt (e.g. the IP Address. The audit data is generated as follows:

Each successful remote login is stored as follows: mgd 70652 UI_AUTH_EVENT [junos@2636.1.1.1.2.164 username="root" authentication-level="super-user"] Authenticated user 'root' assigned to class 'super-user' mgd 70652 UI_LOGIN_EVENT [junos@2636.1.1.1.2.164 username="root" class-name="super-user" local-peer="" pid="70652" ssh-connection="10.223.5.251 53476 10.204.134.54 22" client-mode="cli"] User 'root' login, class 'super-user' [70652], ssh-connection '10.223.5.251 53476 10.204.134.54 22', client-mode 'cli'

Each unsuccessful remote login is stored as follows: sshd - SSHD_LOGIN_FAILED [junos@2636.1.1.1.2.164 username="root" source-address="10.223.5.251"] Login failed for user 'root' from host '10.223.5.251'

Each successful local login is stored as follows: login 2671 LOGIN_INFORMATION [junos@2636.1.1.1.2.164 username="root" hostname="[unknown]" tty-name="ttyu0"] User root logged in from host [unknown] on device ttyu0 login 2671 LOGIN_ROOT [junos@2636.1.1.1.2.164 username="root" hostname="[unknown]" tty-name="ttyu0"] User root logged in as root from host [unknown] on device ttyu0

Each unsuccessful local login is stored as follows: login 70818 LOGIN_PAM_ERROR [junos@2636.1.1.1.2.164 username="root" error-message="error in service module"] Failure while authenticating user root: error in service module login 70818 LOGIN_FAILED [junos@2636.1.1.1.2.164 username="root" source-address="ttyu0"] Login failed for user root from host ttyu0

FIA_UAU.7

No additional events or audit record content

FIA_X509_EXT.1/ Rev

The TOE records each unsuccessful attempt to validate a certificate and any addition, replacement of removal of trust anchors in the TOE's trust store. The TOE also stores the reason for the failure of the certificate validation identification of certificates added, replaced or removed as trust anchor in the TOE's trust store.

Addition of trust anchor:

<182>1 2023-02-22T07:21:57.600Z host mgd 13150 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.129 username="root" action="set" pathname="[security pki ca-profile rootCA ca-identity]" delimiter="" data="unconfigured" value="rootCA"] User 'root' set: [security pki ca-profile rootCA ca-identity] unconfigured -- "rootCA"

<29>1 2023-02-22T07:22:24.769Z host pkid 11250 PKID_PV_CERT_LOAD [junos@2636.1.1.1.2.129 type-string="rootCA"] Certificate rootCA has been successfully loaded

Removal of trust anchor:

<182>1 2023-02-22T07:24:47.471Z host mgd 13150 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.129 username="root" action="delete" pathname="[security pki ca-profile rootCA]" delimiter="" value=""] User 'root' delete: [security pki ca-profile rootCA]

<29>1 2023-02-22T07:24:56.433Z host pkid 11250 PKID_PV_CERT_DEL [junos@2636.1.1.1.2.129 type-string="rootCA"] Certificate deletion has occurred for rootCA

FIA_X509_EXT.2

No additional events or audit record content

FIA_X509_EXT.3

No additional events or audit record content

FMT_MOF.1/ Functions

No additional events or audit record content

FMT_MOF.1/ ManualUpdate

The TOE shall record each attempt to initiate a manual update of the software. The log entry is as follows: UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.164 username="sec-officer" command="request system software add /var/tmp/ junos-install-srxsme-mips-64-24.4R1.9.tgz no-validate "] User 'sec-officer', command 'request system software add /var/tmp/ junos-install-srxsme-mips-64-24.4R1.9.tgz no-validate'

FMT_MOF.1/ Services

No additional events or audit record content

FMT_MTD.1/ CoreData

No additional events or audit record content

FMT_MTD.1/ CryptoKeys

The TOE records the generation of the SSH keys as follows: ssh-keygen 2706 - - Generated SSH key file /root/.ssh/id_rsa.pub with fingerprint SHA256:EQotXjlahhlVplg + YBLbFR3TdmJMpm6D1FSjRo6lVE4 ssh-keygen 2714 - - Generated SSH key file /root/.ssh/id_ecdsa.pub with fingerprint SHA256:ubQWoesME9bpOT1e/ sYv871hwWUzSG8hNqyMUe1cNc0

The TOE records the generation of the IPSEC keys as follows:

pkid 2458 PKID_PV_KEYPAIR_GEN [junos@2636.1.1.1.2.164 argument1="384" argument2="ECDSA" argument3="cert1"] A 384 bit ECDSA key-Pair has been generated for cert1

pkid 2458 PKID_PV_KEYPAIR_GEN [junos@2636.1.1.1.2.164 argument1="4096" argument2="RSA" argument3="cert2"] A 4096 bit RSA key-Pair has been generated for cert2

FMT_SMF.1

See below

FMT_SMR.2

No additional events or audit record content

FPT_APW_EXT.1

No additional events or audit record content

FPT_FLS.1/SelfTest

No additional events or audit record content

FPT_SKP_EXT.1

No additional events or audit record content

FPT_STM_EXT.1

The TOE records each discontinuous changes to time, whether Administrator actuated or changed through an automated process. The old and new values for the time, and the origin of the attempt to change time for success and failure (such as, IP address) is recorded as follows: mgd 71079 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.164 username="root" command="set date 202005201815.00 "] User 'root', command 'set date 202005201815.00 ' mgd 71079 UI_COMMIT_PROGRESS [junos@2636.1.1.1.2.164 message="signaling 'Network security daemon', pid 2641, signal 31, status 0 with notification errors enabled"] Commit operation in progress: signaling 'Network security daemon', pid 2641, signal 31, status 0 with notification errors enabled nsd 2641 NSD_SYS_TIME_CHANGE - System time has changed

FPT_TST_EXT.1

No additional events or audit record content

FPT_TST_EXT.3

No additional events or audit record content

FPT_TUD_EXT.1

The TOE records the initiation of update, and the result of the update attempt (success or failure). The resulting log entry is as follows: UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.164 username="sec-officer" command="request system software add /var/tmp/ junos-install-srxsme-mips-64-24.4R1.9.tgz no-validate "] User 'sec-officer', command 'request system software add /var/tmp/ junos-install-srxsme-mips-64-24.4R1.9.tgz no-validate'

FTA_SSL_EXT.1

The TOE records the termination of a local interactive session by the session locking mechanism in the following format: cli - UI_CLI_IDLE_TIMEOUT [junos@2636.1.1.1.2.164 username="root"] Idle timeout for user 'root' exceeded and session terminated

FTA_SSL.3

The TOE records the termination of a remote session by the session locking mechanism in the following format: cli - UI_CLI_IDLE_TIMEOUT [junos@2636.1.1.1.2.164 username="root"] Idle timeout for user 'root' exceeded and session terminated

FTA_SSL.4

The TOE records the termination of an interactive session in the following format: mgd 71668 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.164 username="root"] User 'root' logout

FTA_TAB.1

No additional events or audit record content

FTP_ITC.1

The TOE records the initiation of the trusted channel, a termination of the trusted channel, and each failure of the trusted channel functions. In each audit records, the TOE stores the identification of the initiator, and the target of the failed trusted channels establishment attempt.

Initiation of the trusted path is recorded as follows: sshd 72418 - - Accepted keyboard-interactive/pam for root from 10.223.5.251 port 42482 ssh2

Termination or failure of the trusted path is recorded as follows: sshd 72418 - - Disconnected from user root 10.223.5.251 port 42482 Failure of the trusted path sshd - SSHD_LOGIN_FAILED [junos@2636.1.1.1.2.164 username="root" source-address="10.223.5.251"] Login failed for user 'root' from host '10.223.5.251'

FTP_ITC.1/VPN

Initiation of the trusted channel:

<30>1 2025-06-20T19:59:15.285Z host kmd 13923 KMD_PM_SA_ESTABLISHED [junos@2636.1.1.1.2.134 local-address="2.2.2.1" remote-address="2.2.2.2" local-initiator="ipv4_subnet(any:0,[0..7]=0.0.0.0/0)" remote-responder="ipv4_subnet(any:0,[0..7]=0.0.0.0/0)" argument1="inbound" index1="2764342498" index2="0" mode="Tunnel" type="dynamic" traffic-selector-name="" first-forwarding-class="" tunnel-id="131073"] Local gateway: 2.2.2.1, Remote gateway: 2.2.2.2, Local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Direction: inbound, SPI: 0xa4c484e2, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: FC Name: , tunnel-id: 131073

Termination of the trusted channel:

Jun 5 07:18:19 host_SITE kmd[10477]: KMD_VPN_DOWN_ALARM_USER: VPN VPN_POLICY from 203.0.113.5 is down. Local-ip: 192.0.2.1, Gateway: HQ-GW, Tunnel-ID: 131073

Failure of the trusted channel functions:

Apr 27 09:17:46 host kmd[1447]: IKE negotiation failed with error: Timed out. IKE Version: 1, VPN: Central‑VPN, Gateway: Central‑GW, Local: 10.160.243.226/500, Remote: 198.51.100.114/500

FTP_TRP.1/Admin

The TOE records the initiation of the trusted path, a termination of the trusted path, and each failure of the trusted path functions.

Initiation of the trusted path is recorded as follows: sshd 72418 - - Accepted keyboard-interactive/pam for root from 10.223.5.251 port 42482 ssh2

Termination of the trusted path is recorded as follows: sshd 72418 - - Disconnected from user root 10.223.5.251 port 42482

Failure of the trusted path is recorded as follows: sshd - SSHD_LOGIN_FAILED [junos@2636.1.1.1.2.164 username="root" source-address="10.223.5.251"] Login failed for user 'root' from host '10.223.5.251'

FFW_RUL_EXT.1

The TOE records each application of rules configured with the ‘log’ operation. For each entry, the TOE stores the source and destination addresses, the source and destination ports, and the Transport Layer Protocol TOE Interface as follows: RT_FLOW - RT_FLOW_SESSION_CREATE [junos@2636.1.1.1.2.164 source-address="1.1. 1.2" source-port="10001" destination-address="2.2.2.2" destination-port="21" connection-tag="0" service-name="junos-ftp" nat-source-address="1.1.1.2" nat-source-port="10001" nat-de stination-address="2.2.2.2" nat-destination-port="21" nat-connection-tag="0" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" protoco l-id="6" policy-name="p1" source-zone-name="ZO_A" destination-zone-name="ZO_B" session-id-32="5" username="N/A" roles="N/A" packet-incoming-interface="ge-0/0/0.0" application="UNKN OWN" nested-application="UNKNOWN" encrypted="UNKNOWN" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp= "N/A" dst-vrf-grp="N/A"] session created 1.1.1.2/10001->2.2.2.2/21 0x0 junos-ftp 1.1.1.2/10001->2.2.2.2/21 0x0 N/A N/A N/A N/A 6 p1 ZO_A ZO_B 5 N/A(N/A) ge-0/0/0.0 UNKNOWN UNKNOWN UNKNOWN N/A N/A -1 N/A N/A N/A

The TOE also stores an indication of packets dropped due to too much network traffic. For each indication, the TOE stores the TOE interface that is unable to process packets, and the Identifier of rule causing packet drop as follows: RT_FLOW - RT_FLOW_SESSION_DENY [junos@2636.1.1.1.2.164 source-address="1.1.1. 2" source-port="10001" destination-address="2.2.2.2" destination-port="21" connection-tag="0" service-name="junos-ftp" protocol-id="6" icmp-type="0" policy-name="p2" source-zone-na me="ZO_A" destination-zone-name="ZO_B" application="UNKNOWN" nested-application="UNKNOWN" username="N/A" roles="N/A" packet-incoming-interface="ge-0/0/0.0" encrypted="No" reason="D enied by policy" session-id-32="3" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp="N/A" dst-vrf-grp=" N/A"] session denied 1.1.1.2/10001->2.2.2.2/21 0x0 junos-ftp 6(0) p2 ZO_A ZO_B UNKNOWN UNKNOWN N/A(N/A) ge-0/0/0.0 No Denied by policy 3 N/A N/A -1 N/A N/A N/A

FFW_RUL_EXT.2

No additional events or audit record content

IPS_ABD_EXT.1

Inspected traffic matches an anomaly-based IPS policy:

<14>1 2025-06-24T09:10:03.127Z host RT_IDP - IDP_ATTACK_LOG_EVENT [junos@2636.1.1.1.2.134 epoch-time="1750756203" message-type="SIG" source-address="2.2.2.2" source-port="0" destination-address="3.3.3.2" destination-port="65029" protocol-name="ICMP" service-name="SERVICE_IDP" application-name="ICMP-ECHO-REPLY" rule-name="RULE_1" rulebase-name="IPS" policy-name="IPS_POLICY" export-id="1048576" repeat-count="0" action="DROP_PACKET" threat-severity="HIGH" attack-name="Attack_Sig_ICMP_Type" nat-source-address="0.0.0.0" nat-source-port="0" nat-destination-address="0.0.0.0" nat-destination-port="0" elapsed-time="0" inbound-bytes="0" outbound-bytes="0" inbound-packets="0" outbound-packets="0" source-zone-name="trust" source-interface-name="ge-0/0/2.0" destination-zone-name="untrust" destination-interface-name="ge-0/0/3.0" packet-log-id="0" alert="no" username="N/A" roles="N/A" xff-header="N/A" cve-id="N/A" session-id="39" message="-"] IDP: at 1750756203, SIG Attack log <2.2.2.2/0->3.3.3.2/65029> for ICMP protocol and service SERVICE_IDP application ICMP-ECHO-REPLY by rule RULE_1 of rulebase IPS in policy IPS_POLICY. attack: id=1048576, repeat=0, action=DROP_PACKET, threat-severity=HIGH, name=Attack_Sig_ICMP_Type, NAT <0.0.0.0:0->0.0.0.0:0>, time-elapsed=0, inbytes=0, outbytes=0, inpackets=0, outpackets=0, intf:trust:ge-0/0/2.0->untrust:ge-0/0/3.0, packet-log-id: 0, alert=no, username=N/A, roles=N/A, xff-header=N/A, cve-id=N/A, session-id=39 and misc-message -

IPS_SBD_EXT.1

Inspected traffic matches a signature-based IPS rule with logging enabled:

<14>1 2022-08-05T13:05:12.092Z host RT_IDP - IDP_ATTACK_LOG_EVENT [junos@2636.1.1.1.2.129 epoch-time="1659704712" message-type="SIG" source-address="10.1.1.146" source-port="1" destination-address="10.1.3.161" destination-port="1" protocol-name="IPIP" service-name="SERVICE_IDP" application-name="NONE" rule-name="1" rulebase-name="IPS" policy-name="deny-policy" export-id="1048576" repeat-count="0" action="DROP" threat-severity="INFO" attack-name="IPv4-version" nat-source-address="0.0.0.0" nat-source-port="0" nat-destination-address="0.0.0.0" nat-destination-port="0" elapsed-time="0" inbound-bytes="0" outbound-bytes="0" inbound-packets="0" outbound-packets="0" source-zone-name="trust" source-interface-name="reth1.0" destination-zone-name="untrust" destination-interface-name="reth2.0" packet-log-id="0" alert="yes" username="N/A" roles="N/A" xff-header="N/A" cve-id="N/A" session-id="181445" message="-"] IDP: at 1659704712, SIG Attack log <10.1.1.146/1->10.1.3.161/1> for IPIP protocol and service SERVICE_IDP application NONE by rule 1 of rulebase IPS in policy deny-policy. attack: id=1048576, repeat=0, action=DROP, threat-severity=INFO, name=IPv4-version, NAT <0.0.0.0:0->0.0.0.0:0>, time-elapsed=0, inbytes=0, outbytes=0, inpackets=0, outpackets=0, intf:trust:reth1.0->untrust:reth2.0, packet-log-id: 0, alert=yes, username=N/A, roles=N/A, xff-header=N/A, cve-id=N/A, session-id=181445 and misc-message –

IPS_IPB_EXT.1

Inspected traffic matches a list of known-good or known-bad addresses applied to an IPS policy:

<14>1 2022-08-05T10:55:54.403Z host RT_FLOW - RT_FLOW_SESSION_CREATE [junos@2636.1.1.1.2.129 source-address="10.1.3.161" source-port="0" destination-address="10.1.1.146" destination-port="0" connection-tag="0" service-name="icmp" nat-source-address="10.1.3.161" nat-source-port="0" nat-destination-address="10.1.1.146" nat-destination-port="0" nat-connection-tag="0" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" protocol-id="1" policy-name="known-good-policy" source-zone-name="untrust" destination-zone-name="trust" session-id="168100" username="N/A" roles="N/A" packet-incoming-interface="reth2.0" application="UNKNOWN" nested-application="UNKNOWN" encrypted="UNKNOWN" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp="N/A" dst-vrf-grp="N/A" tunnel-inspection="Off" tunnel-inspection-policy-set="root" source-tenant="N/A" destination-service="N/A"] session created 10.1.3.161/0->10.1.1.146/0 0x0 icmp 10.1.3.161/0->10.1.1.146/0 0x0 N/A N/A N/A N/A 1 known-good-policy untrust trust 168100 N/A(N/A) reth2.0 UNKNOWN UNKNOWN UNKNOWN N/A N/A -1 N/A N/A N/A Off root N/A N/A

<14>1 2022-08-05T10:14:49.398Z host RT_FLOW - RT_FLOW_SESSION_DENY [junos@2636.1.1.1.2.129 source-address="10.1.1.146" source-port="0" destination-address="10.1.3.161" destination-port="0" connection-tag="0" service-name="icmp" protocol-id="1" icmp-type="8" policy-name="known-bad-policy" source-zone-name="trust" destination-zone-name="untrust" application="UNKNOWN" nested-application="UNKNOWN" username="N/A" roles="N/A" packet-incoming-interface="reth1.0" encrypted="No" reason="Denied by policy" session-id="163556" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp="N/A" dst-vrf-grp="N/A" source-tenant="N/A" destination-service="N/A"] session denied 10.1.1.146/0->10.1.3.161/0 0x0 icmp 1(8) known-bad-policy trust untrust UNKNOWN UNKNOWN N/A(N/A) reth1.0 No Denied by policy 163556 N/A N/A -1 N/A N/A N/A N/A N/A

PS_NTA_EXT.1

Modification of which IPS policies are active on a TOE interface:

<182>1 2023-09-27T10:12:14.782Z host mgd 39458 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.129 username="root" action="set" pathname="[security zones security-zone trust interfaces reth1.0]" delimiter="" value=""] User 'root' set: [security zones security-zone trustinterfaces reth1.0]

<182>1 2023-09-27T10:12:41.394Z host mgd 39458 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.129 username=" root " action="set" pathname="[security policies from-zone trust to-zone untrust policy bypass then permit application-services idp-policy]" delimiter="" data="unconfigured" value="IDP_src"] User 'root' set: [security policies from-zone trust to-zone untrust policy bypass then permit application-services idp-policy] unconfigured -- "IDP_src"

Enabling/disabling a TOE interface with IPS policies applied:

<182>1 2023-09-27T10:16:32.546Z host mgd 39458 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.129 username="root" action="set" pathname="[interfaces reth1 unit 0]" delimiter="" data="unconfigured" value="disable"] User 'root' set: [interfaces reth1 unit 0] unconfigured -- "disable"

Modification of which mode(s) is/are active on a TOE interface:

N/A, the TOE always operates in inline mode.

FPF_RUL_EXT.1

The TOE records an application of rules configured with the ‘log’ operation, With each entry, the TOE records the source and destination addresses, the source and destination ports, and the Transport Layer Protocol TOE Interface in the following format: RT_FLOW - RT_FLOW_SESSION_CREATE [junos@2636.1.1.1.2.164 source-address="1.1. 1.2" source-port="10001" destination-address="2.2.2.2" destination-port="53" connection-tag="0" service-name="junos-dns-udp" nat-source-address="1.1.1.2" nat-source-port="10001" na t-destination-address="2.2.2.2" nat-destination-port="53" nat-connection-tag="0" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" pro tocol-id="17" policy-name="p1" source-zone-name="A" destination-zone-name="B" session-id-32="1" username="N/A" roles="N/A" packet-incoming-interface="ge-0/0/0.0" application="UNKNO WN" nested-application="UNKNOWN" encrypted="UNKNOWN" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp=" N/A" dst-vrf-grp="N/A"] session created 1.1.1.2/10001->2.2.2.2/53 0x0 junos-dns-udp 1.1.1.2/10001->2.2.2.2/53 0x0 N/A N/A N/A N/A 17 p1 A B 1 N/A(N/A) ge-0/0/0.0 UNKNOWN UNKNOWN UN KNOWN N/A N/A -1 N/A N/A N/A

The TOE also records an Indication of packets dropped due to too much network traffic. With each entry, the TOE records the TOE interface that is unable to process packets in the following format: """PERF_MON - RTPERF_CPU_UTIL_MAX [junos@2636.1.1.1.2.164 fpc-slot=""""0"""" pic-slot=""""0""""] FPC 0 PIC 0 CPU Utilization greater than 99, expect packet loss"" ""PERF_MON - RTPERF_CPU_THRESHOLD_EXCEEDED [junos@2636.1.1.1.2.164 fpc-slot=""""0"""" pic-slot=""""0"""" current-value=""""93""""] FPC 0 PIC 0 CPU utilization exceeds threshold, current value = 93"" ""RT_FLOW - FLOW_RESOURCE_CHANGE [junos@2636.1.1.1.2.164 resource-name=""""session table"""" reason=""""is full""""] Flow resource session table is full"""

The TOE also implements a rich set of management functions. The management functions are expressed in FMT_SMF.1, FMT_SMF.1/VPN, FMT_SMF.1/FFW, and FMT_SMF.1/IPS. For each management function, there are specific audit functions to ensure that each management access is properly logged.

Table 2describes the audit functions related to the management functions.

Table 2: Auditable Events
Management Function How Event is Generated

Ability to administer the TOE remotely

Refer to the events listed in this table.

Ability to administer the TOE locally

Refer to the events listed in this table.

Ability to start and stop services

Login as security-officer

security-officer@ host:fips>request system reboot
Reboot the system ? [yes,no] (no)

Ability to re-enable an Administrator account

root@fips#set system login user securityofficer authentication plain-text-password 
New password: 
Retype new password:
root@fips#set system login user securityofficer class super-user
Ability to reset the password for security-officer
root@fips#set system login user securityofficer authentication plain-text-password 
New password: 
Retype new password:

Ability to check Syslog

Verify resetting passwords behavior through audit logs

root@fips>show log /var/log/messages1 | grep "UI_CFG_AUDIT_SET: User 'securityofficer'
set: \[system login user securityofficer authentication\].*unconfigured" | except regress|count

Count: 2 lines

Ability to configure the access banner

See Sect. 5.

Ability to configure the remote session inactivity time before session termination

See FIA_AFL.1

Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates

See FPT_TUD_EXT.1

Ability to configure local audit behaviour (e.g. changes to storage location for audit; changes to behaviour when local audit storage space is full; changes to local audit storage size)
security-officer@host:fips#set system syslog archive files
Ability to modify the behaviour of the transmission of audit data to an external IT entity

Generate an RSA public key on the remote syslog server

ssh-keygen -b 2048 -t rsa -C 'syslogmonitor key pair' -f ~/.ssh/syslog-monitor

[edit system login] security-officer@host:fips# set class monitor permissions trace
[edit system login] security-officer @host:fips#set user syslog-mon class monitor authentication ssh-rsa "public-key"
[edit system services] securityadministrator@ host:fips#set netconf ssh
[edit system] security-officer@host:fips#set syslog file messages any any commit on the remote syslog server
 $ eval ssh-agent -s 
 $ ssh-add ~/.ssh/syslog-monitor 
Ability to manage cryptographic keys

Ability to manage the trusted public keys database

Host_machine#ssh-keygen -t rsa -f $HOME/.ssh/id_ssh_rsa_2048 -N -b 2048

Generating public/private rsa key pair.

/root/.ssh/id_ssh_toby_rsa_2048 already exists. Overwrite (y/n)? Your identification has been saved in /root/.ssh/id_ssh_toby_rsa_2048. Your public key has been saved in /root/.ssh/id_ssh_toby_rsa_2048.pub. The key fingerprint is: SHA256:m8ToMFz77/3rLDCK2rNFv9MaXpB0qmZUqAJM AEIX6X0 root@fips-qnclnx1. englab.juniper.net The key's randomart image is: +---[RSA 2048]----+ |*o.oo | |.o.. . | | + . . . o . | | + o E o + | | = = S + | | = = =o. | | ..O.o+. | | .o+.o.=o. | | ..oo .*o.+=. | +----[SHA256]-----+ Toby-1960280-10.48.155.181% cat $HOME/.ssh/id_ssh_rsa_2048.pub ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDMACOnJHF0UU +3fLO5ji7y9yBBQqolFjgGZ4PZsxOBW44NTYw1yp3cd dih9XLEo5rGctThJfth6qIwLTkLdmw8FUIKvqU3szRz tEuO/OKgchhi3E0YoPLBZI5M++Qth5e+hA65M/ 8Rub4CH2xkt2IIMZRDi51SLYecY0eIpGYs77o+u93x/ rAe5BjooAfKe8UCwJRr2yxuZU/ Xd2U0d6fFVASYIE8dvYI83chrLCC/ WbaB3jUZk7tRumPlyq05vT0RXxzbzpffonRYsaaRnxP oc8xDr9uyDsiIQnA8cMM7H6ZxNHTfPOWSds1fraLEZs rsTOMrMBln5RNBZTc8sgbB root@fips-qnclnx1.

security-officer@host:fips#set system login user syslog-mon authentication ssh-rsa "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDMACOnJHF0UU +3fLO5ji7y9yBBQqolFjgGZ4PZsxOBW44NTYw1yp3cd dih9XLEo5rGctThJfth6qIwLTkLdmw8FUIKvqU3szRz tEuO/OKgchhi3E0YoPLBZI5M++Qth5e+hA65M/ 8Rub4CH2xkt2IIMZRDi51SLYecY0eIpGYs77o+u93x/ rAe5BjooAfKe8UCwJRr2yxuZU/ Xd2U0d6fFVASYIE8dvYI83chrLCC/ WbaB3jUZk7tRumPlyq05vT0RXxzbzpffonRYsaaRnxP oc8xDr9uyDsiIQnA8cMM7H6ZxNHTfPOWSds1fraLEZs rsTOMrMBln5RNBZTc8sgbB root@fips-qnclnx1. englab.juniper.net" security-officer@host:fips#set system login user syslog-mon class super-user

Security Administrator may unlock an account that is locked from remote access (for example, SSH):

Thu May 09 15:09:46 [user@ttbgshell011:~] ssh test@nms-mx304-a Password: Password: Password: Received disconnect from 10.209.4.145 port 22:2: Too many password failures for test Disconnected from 10.209.4.145 port 22 Thu May 09 20:01:19 [user@ttbg-shell011:~] [edit] root@host# run show system login lockout User Lockout start Lockout end test 2024-05-09 20:01:04 IST 2024-05-09 20:05:04 IST

[edit] root@host# sshd: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'test' has been locked out from logins sshd: PAM_USER_LOCK_LOGIN_REQUESTS_DENIED: Login requests from host '10.220.196.34' are denied sshd: PAM_USER_LOCK_ACCOUNT_LOCKED: Account for user test is locked. [edit] root@host# run show system login lockout User accounts not locked [edit] root@host# run show system uptime Current time: 2024-05-09 20:03:10 IST Time Source: LOCAL CLOCK System booted: 2024-05-07 19:19:44 IST (2d 00:43 ago) Protocols started: 2024-05-07 19:22:16 IST (2d 00:40 ago) Last configured: 2024-05-09 20:00:29 IST (00:02:41 ago) by root 8:03PM up 2 days, 43 mins, 1 users, load averages: 0.21, 0.15, 0.10 [edit] root@host# mgd[78360]: LIBJNX_LOGIN_ACCOUNT_UNLOCKED: Account for user 'test' has been unlocked for logins

Ability to configure the cryptographic functionality
security-officer@host:fips#set system services ssh
 security-officer@host:fips#set system services ssh ciphers aes128-ctr
Ability to configure thresholds for SSH rekeying

See FCS_SSH_EXT.1

Ability to configure the lifetime for IPsec SAs

See FCS_IPSEC_EXT.1

Ability to set the time which is used for time-stamps

See FCS_NTP_EXT.1

Ability to configure NTP See Sect. 4.
Ability to configure the reference identifier for the peer

See FCS_IPSEC_EXT.1

Ability to manage the TOE’s trust store and designate X509.v3 certificates as trust anchors

See FCS_IPSEC_EXT.1

Ability to configure the local session inactivity time before session termination or locking

See FIA_AFL.1

Ability to configure the authentication failure parameters for FIA_AFL.1

See FIA_AFL.1

Ability to manage the trusted public keys database

See FCS_IPSEC_EXT.1

All management activities of TSF data (including creation, modification and deletion of firewall rules).

<30>1 2020-08-11T11:15:00.025-07:00 cartier nsd 2095 NSD_SYS_TIME_CHANGE - System time has changed. <38>1 2020-08-11T11:15:25.214-07:00 cartier init - - - chassis-control (PID 2059) exited with status=69 <38>1 2020-08-11T11:15:25.217-07:00 cartier init - - - chassis-control (PID 47908) started <29>1 2020-08-11T11:16:08.805-07:00 cartier chassisd 47908 CHASSISD_RECONNECT_SUCCESSFUL - Successfully reconnected on soft restart

In addition, Juniper Networks recommends:

  • To capture all changes to the configuration.

  • To store logging information remotely.

For more information on log details, see Specifying Log File Size, Number, and Archiving Properties