N2000H V3 Appliance
User Guide
5 System Security Policy
Issue 04 (2018-11-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies
Co., Ltd.
120
Send unencrypted password to connect to third-party SMB Server:
Disabled
Microsoft Network Server
Amount of idle time required before disconnecting session: 15 minutes
Digitally sign communications (always): Enabled
Digitally sign communications (if client agrees): Enabled
Disconnect clients when logon hours expire: Enabled
Server SPN target name validation level: Accept if provided by client
Network Access
Allow anonymous SID/name translation: Disabled
Do not allow anonymous enumeration of SAM accounts: Enabled
Do not allow anonymous enumeration of SAM accounts and shares:
Enabled
Let everyone permissions apply to anonymous users: Disabled
Named pipes that can be accessed anonymously: samr
Remotely accessible registry paths:
System\CurrentControlSet\Control\ProductOptions,
System\CurrentControlSet\Control\Server Applications,
Software\Microsoft\Windows NT\CurrentVersion
Remotely accessible registry paths and subpaths:
System\CurrentControlSet\Control\Print\Printers,
System\CurrentControlSet\Services\Eventlog, Software\Microsoft\OLAP
Server, Software\Microsoft\Windows NT\CurrentVersion\Print,
Software\Microsoft\Windows NT\CurrentVersion\Windows,
System\CurrentControlSet\Control\ContentIndex,
System\CurrentControlSet\Control\Terminal Server,
System\CurrentControlSet\Control\Terminal Server\UserConfig,
System\CurrentControlSet\Control\Terminal
Server\DefaultUserConfiguration, Software\Microsoft\Windows
NT\CurrentVersion\Perflib,
System\CurrentControlSet\Services\SysmonLog
Restrict anonymous access to named pipes and shares: Enabled
Shares that can be accessed anonymously:
Sharing and security model for local accounts: Classic - local users
authenticate as themselves
Network Security
Allow Local System to use computer identity for NTLM: Enabled
Allow LocalSystem NULL session fallback: Disabled
Allow PKU2U authentication requests to this computer to use online
identities: Disabled