Asentria SiteBoss 530 User Manual
56
RTS (Real Time Sockets)
Out of the box the S530 allows connections to TCP port 220x unauthenticated. So unauthorized access to FILEx data
is possible unless you tighten RTS via the authorization controls in RADIUS or User Profiles security modes.
Remember that just like SNMP, Telnet, and FTP, any login credentials you require for RTS connections are passed in
the clear, so anyone eavesdropping on the network could gain unauthorized access. To limit exposure of the user
password, use RADIUS/CHAP or User Profiles with one-time password or challenge response. Alternatively, you can
forbid RTS connections altogether with the
sec.connectvia
setting.
Web UI (User Interface)
The S530 supports both HTTP and HTTPS. Like SNMP, Telnet, and FTP, HTTP is vulnerable to eavesdropping.
Therefore to tighten security for web UI access, do not use it or only access the unit via HTTPS (which is encrypted
with SSL).
Button Unlock
With the Button Unlock feature, you can regain access to a unit that you have been locked out of. This is meant as an
insurance policy against the only other resort to locking yourself out, which is returning the unit to Asentria.
When this feature is set to ON (default setting), the user can tap the Reset button 5 times quickly (1-2 times per
second), at which point the front-panel LEDs will flash briefly for several seconds, giving the user immediate Console
access using the default MASTER username and password.
These are the settings that are defaulted by this process:
sec.mode
(reset to USER PROFILES)
sec.consolereq
(reset to OFF)
sec.connectvia
(reset to every method of connecting)
"admin/password/MASTER" credentials for the user profile appropriate to the product
If you do not want the Button Unlock feature enabled, for example in environments where physical access is not
assumed to be trusted with access, then be sure to turn it off (
sk sec.button.unlock
=OFF
),et the Button Tap
Allows Console Access in the
Security Settings/General Security Settings
menu to OFF.
If you lock yourself out and gain access again with the Button Unlock feature, remember to reconfigure the settings
that were defaulted by the Button Unlock feature to maintain your prior security configuration!
IP Address Restrictions
feature you can select what kind of network traffic the unit should ignore or heed
based on the source IP address of such IP frames.
VPN
For the highly secure, flexible, and centralized network access control (aside from unplugging the network cable),
use IPsec VPNs to SitePath (Asentria’s secure, unified administration portal software). VPNs are disabled and
unconfigured by default. Refer to SitePath documentation for details on how to manage units with SitePath via
VPN.
Summary of Contents for SiteBoss 530
Page 6: ......