140
How can I improve security?
V!CAS
Trace Port
Information transmitted over the ISDN B and D-channels can be traced
using bricktrace and DIME Trace. The default (7000) TCP port number
can be set to 0 to disable access to the V!CAS’ trace port.
From the SNMP shell enter:
biboAdmTracetcpPort=0
Under Setup Tool see the
menu.
SNMP Port
Access to the V!CAS’ SNMP port number can also be changed (default =
161) or disabled by setting to 0. To disable the SNMP port:
From the SNMP shell enter:
biboAdmSNMPPort=0
Under Setup Tool see the
menu.
This will disable remote SNMP sessions. Configuration over telnet
connections are still possible and must be controlled using Access Lists.
RIP Information
The Routing Interior Protocol is used by routers to learn (and teach) IP
routes. You can control which interfaces the V!CAS learns about new IP
routes using the RIP Receive field for both Ethernet and WAN Partner in-
terfaces using the following menus.
Even though small, outgoing RIP packets contain information about
your internal networks. You can restrict the interfaces the V!CAS broad-
casts RIP information on using the RIP Send fields on the above men-
tioned menus.
NAT
Network Address Translation is an excellent method of controlling access
to an internal network. You can configure NAT for each WAN partner in-
terface that connects your LAN to an “unsecure” network (i.e. Internet).
IP
S
TATIC
S
ETTINGS
IP
SNMP
CM-BNCTP, E
THERNET
A
DVANCED
S
ETTINGS
ADD
WAN P
ARTNER
A
DVANCED
S
ETTINGS