•
Check that the firewall is enabled.
•
For incoming connections, always filter (drop) all unused ports which may
include DNS, L2TP-VPN, SNMP and so on.
•
Check that the default action is “drop” in firewalls and allow only the needed
ports.
•
Set unique passwords for each device.
•
Keep passwords stored in a safe place, for example, Encrypted password
management tool.
•
Check that all unused services are disabled.
•
If possible, allow IP connections only via VPN.
•
Disable all unused services, for example, Dial-in, SMSconfig, serial and
SNMP.
•
Back up the configuration.
Section 4
1MRS757105 B
Cyber security
20
RER601/603
Technical Manual