2106026MNAA | XSERIES
G 5
|
79
Recommendation
Description
Secure access with
security switch
Turn the onboard security switch on to enforce authentication through
bi-level security codes or RBAC.
(See section
9.5 Configure bi-level security with security switch.
)
Configure Bi-level
security codes
Change default security codes to private codes (the default security
code for both level 1 and level 2 is 0000).
(See section
9.5 Configure bi-level security with security switch.
)
Enable Role-Based
Access Control (RBAC)
9.6, Configure Role-Based Access Control
)
Enable Role-Based access and enable authentication for each of the
communication ports.
The default RBAC passwords and security codes should be changed.
Secure Network
connection
The device should only be connected to a protected (by firewall) private
network. It is not intended to be connected to the Internet.
Secure Wi-Fi
®
access
Enable the Wi-Fi Access Point only when required.
The Wi-Fi Access Point should always be password-protected to enforce
authentication of Wi-Fi clients.
The default Wi-Fi Access Point password should be changed to a strong
and private password.
Secure Bluetooth
®
access
Enable Bluetooth only when required.
Enable RBAC authentication on the port. (
authentication on communication ports.)
Secure SSH/SFTP
access
Enable the SSH/SFTP service only when required.
The default SSH/SFTP private keys should be changed for all accounts.
The SSH/SFTP private keys should always be passphrase-protected.
(See section
9.7 Secure the SSH/SFTP service.
)
Secure software
updates
Enable the Totalflow Software Update service only when required.
Limit the ability to enable/disable this service with RBAC.
Manage credentials
All private credentials, keys, and security codes should be stored in safe
locations. Share private credentials, keys, and security codes only with
properly trained and authorized personnel.
Change or update private credentials, keys, and security codes as
needed.
This procedure activates secured access to the XFC
G5
or XRC
G5
by changing the default (OFF) position
of the onboard security switch and configuring bi-level security codes.
IMPORTANT NOTE:
After this procedure is completed, connection to the XFC
G5
or XRC
G5
is
restricted to users with the correct security codes. This procedure requires opening the
enclosure to access to the XFC
G5
or XRC
G5
board.
To enable security:
Open the XFC
G5
or XRC
G5
enclosure door and locate the onboard security switch (S1). See
the figure below.
Summary of Contents for XRC G5
Page 25: ...2106026MNAA XSERIESG5 25 ...