®
smartDEN
IP-Maxi
User Manual
09 Mar 2018
- 62 -
10.
Security considerations
The
smartDEN IP-Maxi
runs a special firmware and do not use a general-purpose
operating system. There are no extraneous IP services found on general-purpose
operating systems (e.g. Telnet, FTP, Finger, etc.) that can be particularly vulnerable.
Web-browser access
A challenge-response authentication is used in login process. When the password
is entered, it is transmitted across the network in encrypted form, so eavesdropping
on the data transmission will not reveal the password. Subsequent transmissions of
the password to "login" onto the device are encrypted and "safe". The only case
when the password is transmitted across the network "in the open", is when it is
being changed and submitted in General Setting form. Therefore, you must set
passwords in a secure environment where you can make sure that no one is
"eavesdropping".
XML/JSON operation
A challenge-response authentication can be used in login process. The password
can be transmitted by custom application across the network in encrypted form.
Web and XML/JSON access can be restricted by IP Address (range of IP
Addresses) or by MAC Address.