background image

 

 

User’s Manual 

5.  Change Default HTTP and Other Service Ports 

We suggest you to change default HTTP and other service ports into any set of numbers 

between 1024~65535, reducing the risk of outsiders being able to guess which ports you 

are using. 

6.  Enable HTTPS 

We  suggest  you  to  enable  HTTPS,  so  that  you  visit  Web  service  through  a  secure 

communication channel. 

7.  Enable Whitelist 

We  suggest  you  to  enable  whitelist  function  to  prevent  everyone,  except  those  with 

specified IP addresses, from accessing the system. Therefore, please be sure to add your 
computer’s IP address and the accompanying equipment’s IP address to the whitelist. 

8.  MAC Address Binding 

We  recommend  you  to  bind  the  IP  and  MAC  address  of  the  gateway  to  the  equipment, 

thus reducing the risk of ARP spoofing. 

9.  Assign Accounts and Privileges Reasonably 

According to business and management requirements, reasonably add users and assign a 

minimum set of permissions to them. 

10.  Disable Unnecessary Services and Choose Secure Modes 

If not needed, it is recommended to turn off some services such as SNMP, SMTP, UPnP, 

etc., to reduce risks. 

If necessary, it is highly recommended that you use safe modes, including but not limited to 

the following services: 

 

SNMP: Choose SNMP v3, and set up strong encryption passwords and authentication 

passwords. 

 

SMTP: Choose TLS to access mailbox server. 

 

FTP: Choose SFTP, and set up strong passwords. 

 

AP hotspot: Choose WPA2-PSK encryption mode, and set up strong passwords. 

11.  Audio and Video Encrypted Transmission 

If your audio and video data contents are very important or sensitive, we recommend that 

you use encrypted transmission function, to reduce the risk of audio and video data being 

stolen during transmission. 

Reminder: encrypted transmission will cause some loss in transmission efficiency. 

12.  Secure Auditing 

 

Check  online  users:  we  suggest  that  you  check  online  users  regularly  to  see  if  the 

Device is logged in without authorization. 

 

Check equipment log: By viewing the logs, you can know the IP addresses that were 

used to log in to your devices and their key operations. 

13.  Network Log 

Due to the limited storage capacity of the equipment, the stored log is limited. If you need 

to save the log for a long time, it is recommended that you enable the network log function 

to ensure that the critical logs are synchronized to the network log server for tracing. 

14.  Construct a Safe Network Environment 

In  order  to  better  ensure  the  safety  of  equipment  and  reduce  potential  cyber  risks,  we 

recommend: 

 

Disable the port mapping function of the router to avoid direct access to the intranet 

devices from external network. 

Содержание PFS3006-4ET-36

Страница 1: ...User s Manual I 6 Port Fast Ethernet Switch with 4 Port PoE User s Manual V1 0 0 V1 0 0 ZHEJIANG DAHUA VISION TECHNOLOGY CO LTD ZHEJIANG DAHUA VISION TECHNOLOGY CO LTD...

Страница 2: ...property damage data loss lower performance or unpredictable result TIPS Provides methods to help you solve a problem or save you time NOTE Provides additional information as the emphasis and supplem...

Страница 3: ...nctions and operations description or errors in print If there is any doubt or dispute we reserve the right of final explanation Upgrade the reader software or try other mainstream reader software if...

Страница 4: ...device in the well ventilated environment Do not block the air vent of the device Use the device at rated input and output voltage Do not dissemble the device without professional instruction Transpo...

Страница 5: ...I Important Safeguards and Warnings III 1 Product Overview 1 Introduction 1 1 1 Features 1 1 2 Typical Application 1 1 3 2 Device Structure 2 Side Panel 2 2 1 Front Panel 2 2 2 PoE Power Supply 2 2 3...

Страница 6: ...Mbps uplink ports Features 1 2 Layer 2 commercial switch Supports IEEE802 3 IEEE802 3u and IEEE802 3x standards MAC auto study and aging MAC address capacity is 2K Supports MDI MDIX self adaptation R...

Страница 7: ...Alive is on IPC can be kept alive 4 Extend Mode In extend mode data can be transmitted up to 250 m in CAT6 cable with a bandwidth of 10 M 5 Link Act Single port Link status indicator 6 PoE Single por...

Страница 8: ...User s Manual 3 PoE Power Supply 2 3 Four 100M RJ45 ports support IEEE802 3af and IEEE802 3at standard power supply...

Страница 9: ...ble the auto check for updates function to obtain timely information of firmware updates released by the manufacturer We suggest that you download and use the latest version of client software Nice to...

Страница 10: ...services SNMP Choose SNMP v3 and set up strong encryption passwords and authentication passwords SMTP Choose TLS to access mailbox server FTP Choose SFTP and set up strong passwords AP hotspot Choose...

Страница 11: ...sted to use VLAN network GAP and other technologies to partition the network so as to achieve the network isolation effect Establish the 802 1x access authentication system to reduce the risk of unaut...

Страница 12: ...User s Manual...

Отзывы: