76
| XSERIES G5 | 2106026MNAA
—
9
Configure security (recommended)
To secure access to the XSeries
G5
devices, review the security features implemented.
Totalflow user interfaces and host products support connection with the XSeries
G5
devices through
several types of communication ports, protocols, and services. These constitute points of entry that
could be subject to inexperienced, unauthorized or malicious access through a point-to-point
connection or a connection established over a network. Local and remote access must be protected by
controlling physical access to the ports, enabling on-board security, or enforcing authentication prior
to establishing a connection using any of the ports.
This section lists the communication ports, services, protocols, and the open Transmission Control
Protocol (TCP) ports that need to be taken into consideration when securing devices.
The table below lists the default communication ports available in XSeries
G5
devices with standard
configuration. These ports are pre-configured from the factory. When enabled, these ports are ready
for use, but are not secured.
Unprotected ports make the full functionality of the device available to any user. Configure security
passcode or role-based authentication to prevent indiscriminate access.
Table 9-1: Default communication ports in XSeries
G5
Wired connections
communication
ports,
default names
Default
state
Default protocol
Security feature available
MMI,
port name:
MMI Serial - COM0
Enabled
Totalflow Local
(Read-only)
Bi-Level Security code authentication or
Role-base Authentication (RBAC)
USB,
port name:
Totalflow - USB
Enabled
Totalflow Local
(Read-only)
Bi-Level Security code authentication or
Role-base Authentication (RBAC)
Ethernet,
port name:
Totalflow
–
TCP
Disabled Totalflow/TCP
(Read-only)
Bi-Level Security code authentication or
Role-base Authentication (RBAC)
COMM1,
port name:
TF
–
Remote
Enabled
Totalflow Remote
(Configurable)
Bi-Level Security code authentication or
Role-base Authentication (RBAC)
The Table below lists the wireless interfaces available in XSeries
G5
devices with standard configuration.
Table 9-2: Wireless interfaces in XSeries
G5
Wireless connections
communication
interfaces
Default
state
Protocol
Security feature available
Wi-Fi,
Wi-Fi Access
Point functionality
Disabled
Totalflow
Local/TCP
Passcode protection and standards-based
Wi-Fi security modes (WPA, WPA2)
Onboard Bluetooth,
Port Name: Bluetooth
Disabled
Totalflow
Local
Role-Based Authentication (RBAC)
Bluetooth via USB
Dongle,
Port Name: Bluetooth
Disabled
Totalflow
Local
Role-Based Authentication (RBAC)
9.2.1
User-enabled services
Services are software processes that run on the XSeries
G5
device. The table below lists user-enabled
services that open access to the embedded software file system. Unauthorized or malicious use of
these services can cause file corruption and render a device inoperable.
Summary of Contents for XFC G5
Page 25: ...2106026MNAA XSERIESG5 25 ...