The Juniper Networks SRX Series Gateway IDPS must have only active Juniper Networks licenses.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-214636
JUSX-IP-000030
SV-214636r385561_rule
Medium
Description
If the IDP or UTM licenses are allowed to lapse, the Juniper SRX IDPS can still inspect traffic and continue to use the outdated signature database for rules, objects, and dynamic groups. However, updates to the signature database cannot be downloaded from Juniper Networks. This puts the network at risk since the updates are used to addresses new CERT and IAVM vulnerabilities.