Device security
2.6
Security configuration
29
UM Security BRS-2A
Release
8.7
05/2022
You can also elect to configure the following advanced user authentication measures as needed
(see on page 36 “Configure advanced user authentication”)
:
Use 802.1X for user authentication.
Use a dedicated authentication policy list.
Configure LDAP or RADIUS access instead of or in addition to the local IAS (Integrated
Authentication Server).
When the device configuration is complete:
Create a backup copy of the configuration.
Include other device-related data like private keys.
2.6.1
Assign a static IP address for the device management
Note:
At the first login with the default password, the device asks you to change the password. Use
a dedicated password according to your password policy
(see on page 19 “Plan a dedicated user
.
The device offers you the following options of assigning a management IP address: Local, DHCP
(delivery state), and BOOTP.
Selecting the setting "Local" (that is: static) helps make the device more immune to potential attacks
via the DHCP or BOOTP protocols.
2.6.2
Disable HiDiscovery access
The HiDiscovery protocol is enabled in the delivery state.
Setting the HiDiscovery protocol to
Off
helps make the device more immune to potential attacks
via the HiDiscovery protocol.
2.6.3
Configure a VLAN dedicated to management access.
Note:
Hirschmann assumes that, when reading this section, you have already performed the
general and security-related configuration planning for the device
(see on page 21 “VLAN plan
considerations depending on redundancy protocols”)
.
The delivery state VLAN ID for management access is 1.
Configure a VLAN dedicated to management access only. This helps make the device more
immune to potential attacks via the network. It may also help improve the reachability of the device
management when there is heavy network traffic.
Note:
If you use the redundancy protocols HIPER Ring or Ring/Network Coupling, use a VLAN
ID ≥2 for management access. Else you are free to use any VLAN ID you like.
Summary of Contents for HIRSCHMANN HiOS-2A
Page 6: ...Contents 6 UM Security BRS 2A Release 8 7 05 2022 ...
Page 8: ...Document History 8 UM Security BRS 2A Release 8 7 05 2022 ...
Page 10: ...Safety instructions 10 UM Security BRS 2A Release 8 7 05 2022 ...
Page 54: ...Network security support 3 11 Configure logging 54 UM Security BRS 2A Release 8 7 05 2022 ...
Page 62: ...Index 62 UM Security BRS 2A Release 8 7 05 2022 ...
Page 66: ......