138
How can I improve security?
V!CAS
How can I improve security?
The V!CAS offers a wide variety of features that make internetworking
and remote access as easy as possible. Though providing access to your
remote sites is important it’s just as important to ensure your networks
are secure. This section outlines some of the things to consider when look-
ing to improve security.
Passwords
Until these settings are changed (and saved in a configuration file) the
V!CAS uses the following default passwords for the three logins.
• admin
bintec
• write
public
• read
public
The write and read users have restricted powers but can still make
temporary changes (see page 30). Once your system is configured you
should change these settings and protect the passwords.
Dial-in Partner Authentication
When adding ISDN dialup partners in the
menu you have the option of using the Calling Line ID feature of ISDN.
This option should always be used by setting
Identify by Calling Number
yes
In addition to CLID the CHAP and PAP authentication protocols are
available by setting
PPP Authentication Protocol
<PAP, CHAP, or both>
Login access via isdnlogin
The isdnlogin program can be used to login to the V!CAS from a remote
ISDN site depending on the Local Number you assigned to the ISDN
Login item under
. Note that if there are no
entries, OR the routing item is assigned and
the isdnLoginOnPPPDispatch variable (only accessible from the SNMP
shell) is set to “allow”, then login calls are also accepted.
ADD
WAN P
ARTNER
I
NCOMING
C
ALL
A
NSWERING
I
NCOMING
C
ALL
A
NSWERING