![Asentria Teleboss 850 Скачать руководство пользователя страница 71](http://html.mh-extra.com/html/asentria/teleboss-850/teleboss-850_user-manual_2981745071.webp)
TeleBoss 850 2.06.280_STD User Manual
Page 65
SSH (Secure Shell)
To enable SSH access to the T850, you must generate a host key with the SSHC command (see the section on
for details). This is the preferred network access method over telnet of course because the traffic is encrypted.
RTS (Real Time Sockets)
Out of the box the T850 allows connections to TCP port 220x unauthenticated. So unauthorized access to FILEx data
is possible unless you tighten RTS via the authorization controls in RADIUS or User Profiles security modes.
Remember that just like SNMP, Telnet, and FTP, any login credentials you require for RTS connections are passed in
the clear, so anyone eavesdropping on the network could gain unauthorized access. To limit exposure of the user
password, use RADIUS/CHAP or User Profiles with one-time password or challenge response. Alternatively, you can
forbid RTS connections altogether with the
sec.connectvia
setting.
Web UI (User Interface)
The T850 supports both HTTP and HTTPS. Like SNMP, Telnet, and FTP, HTTP is vulnerable to eavesdropping.
Therefore to tighten security for web UI access, do not use it or only access the unit via HTTPS (which is encrypted
with SSL).
Button Unlock
With the Button Unlock feature, you can regain access to a unit that you have been locked out of. This is meant as an
insurance policy against the only other resort to locking yourself out, which is returning the unit to Asentria.
When this feature is set to ON (default setting), the user can tap the Reset button 5 times quickly (1-2 times per
second), at which point the front-panel LEDs will flash briefly for several seconds, giving the user immediate Console
access using the default MASTER username and password.
These are the settings that are defaulted by this process:
sec.mode
(reset to USER PROFILES)
sec.consolereq
(reset to OFF)
sec.connectvia
(reset to every method of connecting)
"admin/password/MASTER" credentials for the user profile appropriate to the product
If you do not want the Button Unlock feature enabled, for example in environments where physical access is not
assumed to be trusted with access, then be sure to turn it off (
sk sec.button.unlock
=OFF
), or set the Button Tap
Security Settings/General Security Settings
If you lock yourself out and gain access again with the Button Unlock feature, remember to reconfigure the settings
that were defaulted by the Button Unlock feature to maintain your prior security configuration!
IP Address Restrictions
feature you can select what kind of network traffic the unit should ignore or heed
based on the source IP address of such IP frames.
VPN
For the highly secure, flexible, and centralized network access control (aside from unplugging the network cable), use
IPsec VPNs to SitePath (Asentria’s secure, unified administration portal software). VPNs are disabled and
unconfigured by default. Refer to SitePath documentation for details on how to manage units with SitePath via VPN.
NetPoll Feature
NetPoll is a feature developed for one customer of Asentria’s which all other users will never use. However it can
pose a security risk if it is enabled. When enabled, it causes the T850 to listen on TCP port 3001 for an incoming
connection from the polling machine, which it then accepts. This feature is set using one of the following two Setting
Keys:
sec.connectvia
=ON
sec.connectvia.netpoll
=ON
By default, neither of these Setting Keys are set to these values, so unless they are specifically set as such the T850
will not accept any connection attempt from TCP port 3001.
Содержание Teleboss 850
Страница 6: ......