11-4
Broadmore 1750 - Release 4.6
Security Management (FIPS Mode)
Security Guidance
Potential Security Vulnerabilities
(1) Disabling fipsmode deletes existing user access accounts and cryptographic
keys and reverts the Broadmore to the factory default SuperUser ID and
password, which can deny management access and compromise security. No one
can log in till the Broadmore is rebooted. It is recommended that the fipsmode be
changed only during initial setup and decommissioning.
(2) The Broadmore accepts loose source routed IP packets, so it is recommended
that source routed packets be dropped on routers and firewalls. (See
manufacturer’s instructions.)
(3) The Broadmore RS-232 COM 1 serial port used for “Craft Access” does not
immediately terminate a management session if a user disconnects without typing
“exit”. During the following timeout period, another user can connect without
logging into the RS-232 port and other users are denied access through the
ethernet port. It is recommended that all accounts be created with “Remote
Access” only, except for one failsafe SuperUser account with “Craft Access.”
The craft password should be stored safely in the NOC. When needed, the
SuperUser can log into the craft port, fix things, change the password, log out,
and store the new password back in the NOC.
Initialization and Verification
– When the Broadmore is powered up in the
FIPS mode, the FIPS 140-2 validated software will perform a self-test to verify
software integrity and cryptographic functions. To verify that the Broadmore is
operating in FIPS mode, see
“Help About Security” on page
11-17
.
Key Management
– A DSA private hosts key is required for SSH2 connection
to the Broadmore. A default key is provided for use in initializing the Broadmore
after installation at the customer site. The SuperUser should change this key
before making the Broadmore operational and change it periodically in
accordance with local security practice.
System Clock
– The system clock is used to time stamp all events recorded in the
system log and user audit log. To set the system clock, see
“System Clock” on
page
11-14
.
Содержание Broadmore 1750
Страница 1: ...Broadmore TM 1750 USER MANUAL Part Number 770 0020 DC Product Release 4 6 January 2008 ...
Страница 24: ...xii Broadmore 1750 Release 4 6 Table of Contents ...
Страница 50: ...1 26 Broadmore 1750 Release 4 6 Product Description Alarm Power Module IOM ...
Страница 69: ...CHAPTER 3 Receipt of Product In this Chapter Receipt 3 2 Unpacking 3 2 Inspection 3 3 ...
Страница 72: ...3 4 Broadmore 1750 Release 4 6 Receipt of Product Damage Reporting ...
Страница 82: ...4 10 Broadmore 1750 Release 4 6 Chassis Installation and Grounding AC Power Supply Tray ...
Страница 114: ...6 16 Broadmore 1750 Release 4 6 Electrical Installation Software ...
Страница 188: ...7 74 Broadmore 1750 Release 4 6 Configuration Help ...
Страница 199: ...Broadmore 1750 Release 4 6 8 11 Maintenance and Troubleshooting Slot Statistics for NIM SAM Cards ...
Страница 200: ...8 12 Broadmore 1750 Release 4 6 Maintenance and Troubleshooting Slot Statistics for NIM SAM Cards ...
Страница 234: ...8 46 Broadmore 1750 Release 4 6 Maintenance and Troubleshooting Summary of Front Panel LEDs ...
Страница 244: ...9 10 Broadmore 1750 Release 4 6 Command Line Interface About Command ...
Страница 266: ...10 22 Broadmore 1750 Release 4 6 Security Management FTP Login ...
Страница 302: ...11 36 Broadmore 1750 Release 4 6 Security Management FIPS Mode sshdShow ...
Страница 311: ...Broadmore 1750 Release 4 6 11 45 Security Management FIPS Mode Logging in with SecurID Disabled ...
Страница 314: ...11 48 Broadmore 1750 Release 4 6 Security Management FIPS Mode Logging in with SecurID Enabled ...
Страница 318: ...11 52 Broadmore 1750 Release 4 6 Security Management FIPS Mode Sanitation Procedures ...
Страница 362: ...12 44 Broadmore 1750 Release 4 6 SNMP Configuration Notify Profiles ...
Страница 363: ...APPENDIX A Technical Specifications In this Appendix Broadmore 1750 Platform A 2 Broadmore Modules A 6 ...
Страница 370: ...A 8 Broadmore 1750 Release 4 6 Technical Specifications E3 Unstructured Circuit Emulation SAM ...
Страница 373: ...APPENDIX C Software Error Messages In this Appendix Overview System Errors Setup Errors ...
Страница 383: ...APPENDIX E Chassis Differences ...
Страница 386: ...E 4 Broadmore 1750 Release 4 6 Chassis Differences Software Differences ...
Страница 394: ...F 8 Broadmore 1750 Release 4 6 IPv6 Support Deleting a Network Route ...
Страница 398: ...G 4 Broadmore 1750 Release 4 6 Broadmore Command List Commands Available at the CLI Prompt ...
Страница 408: ...Glossary 10 Broadmore 1750 Release 4 6 Glossary ...