11-4
Broadmore 1750 - Release 4.6
Security Management (FIPS Mode)
Security Guidance
Potential Security Vulnerabilities
(1) Disabling fipsmode deletes existing user access accounts and cryptographic
keys and reverts the Broadmore to the factory default SuperUser ID and
password, which can deny management access and compromise security. No one
can log in till the Broadmore is rebooted. It is recommended that the fipsmode be
changed only during initial setup and decommissioning.
(2) The Broadmore accepts loose source routed IP packets, so it is recommended
that source routed packets be dropped on routers and firewalls. (See
manufacturer’s instructions.)
(3) The Broadmore RS-232 COM 1 serial port used for “Craft Access” does not
immediately terminate a management session if a user disconnects without typing
“exit”. During the following timeout period, another user can connect without
logging into the RS-232 port and other users are denied access through the
ethernet port. It is recommended that all accounts be created with “Remote
Access” only, except for one failsafe SuperUser account with “Craft Access.”
The craft password should be stored safely in the NOC. When needed, the
SuperUser can log into the craft port, fix things, change the password, log out,
and store the new password back in the NOC.
Initialization and Verification
– When the Broadmore is powered up in the
FIPS mode, the FIPS 140-2 validated software will perform a self-test to verify
software integrity and cryptographic functions. To verify that the Broadmore is
operating in FIPS mode, see
“Help About Security” on page
11-17
.
Key Management
– A DSA private hosts key is required for SSH2 connection
to the Broadmore. A default key is provided for use in initializing the Broadmore
after installation at the customer site. The SuperUser should change this key
before making the Broadmore operational and change it periodically in
accordance with local security practice.
System Clock
– The system clock is used to time stamp all events recorded in the
system log and user audit log. To set the system clock, see
“System Clock” on
page
11-14
.
Summary of Contents for Broadmore 1750
Page 1: ...Broadmore TM 1750 USER MANUAL Part Number 770 0020 DC Product Release 4 6 January 2008 ...
Page 24: ...xii Broadmore 1750 Release 4 6 Table of Contents ...
Page 50: ...1 26 Broadmore 1750 Release 4 6 Product Description Alarm Power Module IOM ...
Page 69: ...CHAPTER 3 Receipt of Product In this Chapter Receipt 3 2 Unpacking 3 2 Inspection 3 3 ...
Page 72: ...3 4 Broadmore 1750 Release 4 6 Receipt of Product Damage Reporting ...
Page 82: ...4 10 Broadmore 1750 Release 4 6 Chassis Installation and Grounding AC Power Supply Tray ...
Page 114: ...6 16 Broadmore 1750 Release 4 6 Electrical Installation Software ...
Page 188: ...7 74 Broadmore 1750 Release 4 6 Configuration Help ...
Page 234: ...8 46 Broadmore 1750 Release 4 6 Maintenance and Troubleshooting Summary of Front Panel LEDs ...
Page 244: ...9 10 Broadmore 1750 Release 4 6 Command Line Interface About Command ...
Page 266: ...10 22 Broadmore 1750 Release 4 6 Security Management FTP Login ...
Page 302: ...11 36 Broadmore 1750 Release 4 6 Security Management FIPS Mode sshdShow ...
Page 318: ...11 52 Broadmore 1750 Release 4 6 Security Management FIPS Mode Sanitation Procedures ...
Page 362: ...12 44 Broadmore 1750 Release 4 6 SNMP Configuration Notify Profiles ...
Page 370: ...A 8 Broadmore 1750 Release 4 6 Technical Specifications E3 Unstructured Circuit Emulation SAM ...
Page 373: ...APPENDIX C Software Error Messages In this Appendix Overview System Errors Setup Errors ...
Page 383: ...APPENDIX E Chassis Differences ...
Page 386: ...E 4 Broadmore 1750 Release 4 6 Chassis Differences Software Differences ...
Page 394: ...F 8 Broadmore 1750 Release 4 6 IPv6 Support Deleting a Network Route ...
Page 398: ...G 4 Broadmore 1750 Release 4 6 Broadmore Command List Commands Available at the CLI Prompt ...
Page 408: ...Glossary 10 Broadmore 1750 Release 4 6 Glossary ...