
iPlex Installation and Hardware Specification Guide
91
.
Users are strongly urged to use secure community strings for SNMP access.
In addition to the measures described in this section, users are strongly urged to
deploy firewalls or configure their networks to prevent access from unauthorized
third parties. A few solutions for this are presented later in this chapter.
Denial-of-Service (DoS)
Denial-of-Service happens when external entities are able to crash or incapacitate
the system by subjecting it to specific traffic patterns. In this case, the third party
never gains control of the system, but still makes it unavailable to its legitimate
users.
DoS attacks may or may not explore bugs in the target system.
.
TANDBERG Television does not guarantee that a iPlex directly connected to the
Internet will be able to withstand every type of Denial-of-Service attack. TAND-
BERG Television cannot guarantee that the operation of a iPlex directly connected
to the Internet will be error-free.
It is recommended that the iPlex be protected by a firewall. The remainder of this
chapter explores practical options for deploying a firewall.
Firewall Options
This section discusses options for connecting the iPlex to the Internet. The basic
assumption is that access to the iPlex from the Internet is desired in some fashion,
for remote configuration or debugging (otherwise, the best option is to just con-
nect the control port of the iPlex to a completely isolated network). In this section,
private address
means one of the IP address ranges defined for private networks in
RFC-1918, namely:
•
10.0.0.0/8
•
172.16.0.0/12
•
192.168.0.0/16
NOTE
TANDBERG Television generally makes the
iPlex
MIB available only
to customers and prospective customers. However, for security pur-
poses, one should not rely on that.
NOTE
It is possible to overload most systems simply by sending too many
packets to them. The SCM control port is designed to withstand a
certain amount of hostile traffic, but inspecting a packet and decid-
ing to drop it still takes CPU time; if too many packets are sent,
there may not be cycles available for running the system and there
may be service interruption.
Содержание TANDBERG Television iPlex N20001
Страница 8: ...8...
Страница 12: ...iPlex Installation and Hardware Specifications Guide 12...
Страница 13: ...13 Introducing TANDBERG Television iPlex Chapter 1...
Страница 24: ...24 iPlex Installation and Hardware Specification Guide...
Страница 25: ...25 Hardware Specification and Installation Chapter 2...
Страница 72: ...72 iPlex Installation and Hardware Specification Guide...
Страница 73: ...73 Control Station Setup Chapter 3...
Страница 88: ...88 iPlex Installation and Hardware Specification Guide...
Страница 89: ...89 Connecting iPlex to the Internet Firewall Issues Appendix A...
Страница 98: ...Beta Beta iPlex Installation and Hardware Specifications Guide 98...