Product Affected

J2320, J2350, J4350, J6350, SRX100, SRX210, SRX240, SRX650, SRX3400, SRX3600, SRX5600, SRX5800 Junos 9.4 and later
Medium
5.0

Problem

UAC Infranet Enforcer(IE) resource policies should be applied in the Infranet Auth Table according to the order those policies are listed in the Infranet Controller(IC) Web Admin.

On a Junos IE, these policies are not evaluated in the correct order.

On a ScreenOS IE, these policies are applied in the correct order.

Solution

This issue is resolved in Junos 9.4R4 and any later release posted on or after November 18, 2009. This specifically includes the following and all subsequent releases:
9.4R4, 9.5R4, 9.6R3, 10.0R1, 10.1R1

Workaround

KB16200 [juniper.net] describes how to configure your UAC resource policies such that they get applied in the desired order when the policies get pushed to an SRX or J-series device acting as an Infranet Enforcer.

Severity Assessment

Some policies may not be applied. Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Related Information