• Configuration files can be downloaded from the device. Ensure that configuration files are
adequately protected. The options for achieving this include digitally signing and encrypting
the files, storing them in a secure location, or transmitting configuration files only through
secure communication channels.
Configuration files can be password protected during download. You enter passwords on the
WBM page "System > Load & Save > Passwords".
• When using SNMP (Simple Network Management Protocol):
– Configure SNMP to generate a notification when authentication errors occur.
For more information, see WBM "System > SNMP > Notifications".
– Ensure that the default community strings are changed to unique values.
– Use SNMPv3 whenever possible. SNMPv1 and SNMPv2c are considered non-secure and
should only be used when absolutely necessary.
– If possible, prevent write access above all.
• Use the security functions such as address translation with NAT (Network Address
Translation) or NAPT (Network Address Port Translation) to protect receiving ports from
access by third parties.
• Use WPA2/ WPA2-PSK with AES to protect the WLAN. You can find additional information in
the configuration manual Web Based Management "Security menu".
Secure/ non-secure protocols
• Use secure protocols if access to the device is not prevented by physical protection measures.
• Disable or restrict the use of non-secure protocols. While some protocols are secure (e.g.
HTTPS, SSH, 802.1X, etc.), others were not designed for the purpose of securing applications
(e.g. SNMPv1/v2c, RSTP, etc.).
Therefore, take appropriate security measures against non-secure protocols to prevent
unauthorized access to the device/network. Use non-secure protocols on the device using a
secure connection (e.g. SINEMA RC).
• If non-secure protocols and services are required, ensure that the device is operated in a
protected network area.
• Check whether use of the following protocols and services is necessary:
– Non-authenticated and unencrypted ports
– LLDP
– Syslog
– DHCP options 66/67
– TFTP
– Telnet
– HTTP
– SNMP v1/2c
– Syslog
– SNTP
Security recommendations
SCALANCE W786-x
14
Operating Instructions, 12/2021, A5E03678337-14
Summary of Contents for 6GK5786-1FC00-0AA0
Page 8: ...Introduction SCALANCE W786 x 8 Operating Instructions 12 2021 A5E03678337 14 ...
Page 10: ...Safety notices SCALANCE W786 x 10 Operating Instructions 12 2021 A5E03678337 14 ...
Page 66: ...Maintenance and cleaning SCALANCE W786 x 66 Operating Instructions 12 2021 A5E03678337 14 ...
Page 82: ...Dimension drawings SCALANCE W786 x 82 Operating Instructions 12 2021 A5E03678337 14 ...
Page 84: ...Certification SCALANCE W786 x 84 Operating Instructions 12 2021 A5E03678337 14 ...