Device security
2.6
Security configuration
32
UM Security BRS-2A
Release
8.7
05/2022
2.6.12
Disable loading a configuration profile that lacks a valid fingerprint
Disable the loading of a configuration profile that lacks a valid fingerprint. This helps secure the
device against loading an unsigned configuration profile placed on an external memory and
plugged into the device with the intention that the unsigned configuration profile will take effect after
a reboot.
See the user manual "Configuration" on how to disable loading an unsigned configuration profile
from an external memory.
2.6.13
Disable insecure management protocols
Disable insecure management protocols:
Disable SNMPv1 (delivery state: disabled).
Disable SNMPv2 (delivery state: disabled).
Disable Telnet (delivery state: disabled).
Disable HTTP (delivery state:
enabled
(redirects to HTTPS)).
2.6.14
Configure management IP access restrictions
The device allows restricting the management access to the device to a source IP address range.
You specify the address range by giving an IP address and a netmask.
You can configure the management access IP restrictions individually for each protocol or for a
group of protocols.
Note:
Protocols with the delivery state
Enabled
(bolded) may be useful for the initial configuration
of the device. However, they may be considered insecure for production. Disable these protocols
as soon as you no longer need them.
Confirm that at least one of the configured management access IP restrictions is active. If no
restriction is active, this leads to unrestricted management access for all enabled protocols.
Table 2: Management access protocol overview
Protocol
Recommendation for production
Delivery state
HTTP
Disabled
Enabled
(redirects to HTTPS)
HTTPS
Enabled
Enabled
SNMPv1
Disabled
Disabled
SNMPv2
Disabled
Disabled
SNMPv3
Enabled
Enabled
Telnet
Disabled
Disabled
SSH
Enabled
Enabled
IEC 61850-MMS
Disabled
Disabled
Modbus TCP
Disabled
Disabled
EtherNet/IP
Disabled
Disabled
OPC UA Server
Disabled
Disabled
PROFINET
Disabled
Disabled
Summary of Contents for HIRSCHMANN HiOS-2A
Page 6: ...Contents 6 UM Security BRS 2A Release 8 7 05 2022 ...
Page 8: ...Document History 8 UM Security BRS 2A Release 8 7 05 2022 ...
Page 10: ...Safety instructions 10 UM Security BRS 2A Release 8 7 05 2022 ...
Page 54: ...Network security support 3 11 Configure logging 54 UM Security BRS 2A Release 8 7 05 2022 ...
Page 62: ...Index 62 UM Security BRS 2A Release 8 7 05 2022 ...
Page 66: ......