STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Juniper SRX Services Gateway IDPS Security Technical Implementation Guide

V-214636

CAT II (Medium)

The Juniper Networks SRX Series Gateway IDPS must have only active Juniper Networks licenses.

Rule ID

SV-214636r385561_rule

STIG

Juniper SRX Services Gateway IDPS Security Technical Implementation Guide

Version

V2R1

CCIs

CCI-000366

Discussion

If the IDP or UTM licenses are allowed to lapse, the Juniper SRX IDPS can still inspect traffic and continue to use the outdated signature database for rules, objects, and dynamic groups. However, updates to the signature database cannot be downloaded from Juniper Networks. This puts the network at risk since the updates are used to addresses new CERT and IAVM vulnerabilities.

Check Content

In operational mode, enter show system license.

If the license expiration for idp-sig and all other licenses installed are past today's date, this is a finding.

Fix Text

Update the expired licenses immediately following the procedures on the vendor website.