
Enhancing System Security
System Security Checklist
Administrator’s Guide for Avaya Communication Manager
325
November 2003
f
Administer Authorization Codes.
g
Use a minimum of 11 digits (combination of barrier codes and authorization codes).
h
Assign
Security Violation Notification Remote
to 10 attempts in 2 minutes.
5
If you use vectors:
a
Assign all Vector Directory Numbers (VDN) a unique COR. See the Avaya
Communication Manager Contact Center Guide to ACD Contact Centers and the Avaya
Communication Manager Contact Center Call Vectoring and Expert Agent Selection
(EAS) Guide for more information.
NOTE:
The COR associated with the VDN dictates the calling privileges of the VDN/vector. High
susceptibility to toll fraud exists on vectors that have “collect digits” steps. When a vector
collects digits, it processes those digits back to Communication Manager and if the COR
of the VDN allows it to complete the call off-net, it will do so. For example, the
announcement “If you know your party’s 4-digit extension number, enter it now” results in
4 digits being collected in step 6. If you input “90##” or “900#”, the 4 digits are analyzed
and if “9” points towards ARS and “0” or “00” is assigned in the ARS Analysis Tables and
the VDN COR allows it, the call routes out of the server to an outside local exchange or
long distance operator. The operator then connects the call to the requested number.
b
If vectors associated with the VDN do not require routing the call off-net or via AAR,
assign a unique COR where the FRLis
0
, the
Calling Party Restriction
field is outward,
the
Calling Permissions
field is n on all unique Trunk Group COR.
c
If the vector has a “route-to” step that routes the call to a remote server via AAR, assign a
unique COR with a unique ARS/AAR Partition Group, the lowest FRL to complete an
AAR call, and n on all unique COR assigned to your public network trunking facilities on
the Calling Permissions. Assign the appropriate AAR route patterns on the AAR Partition
Group using the
change aar analysis partition x 2
command.
Tip:
You can use the
display aar analysis print
command to print a copy of your Automatic
Alternate Routing (AAR) setup before making any changes. You can use the printout to
correct any mistakes.
d
If the vector has a “route-to” step that routes the call to off-net, assign a unique COR with
a unique ARS/AAR Partition Group, the lowest FRL to complete an ARS call, and n on
all unique COR assigned to your public network trunking facilities on the Calling
Permissions. Assign the appropriate complete dial string in the “route-to” step of the
vector the unique ARS Partition Group using the
change ars analysis partition x 2
command.
6
On the
Feature Access Code
screen,
Facility Test Calls Access Code
, the
Data Origination
Access Code
, and the
Data Privacy Access Code
fields, change from the default or remove
them.
NOTE:
These codes, when dialed, return system dial tone or direct access to outgoing trunking
facilities. Transfers to these codes can take place via an unsecured vector with “collect
digits” steps or an unsecured voice mail system.