Device security
2.6
Security configuration
30
UM Security BRS-2A
Release
8.7
05/2022
2.6.4
Disable logical access to the Signal Contact
If you do not need the Signal Contact, disable the Signal Contact in the device configuration. In the
delivery state, the Signal Contact is disabled.
If you do need the Signal Contact
(see on page 39 “Signal Contact considerations”)
.
2.6.5
Disable logical access to the Digital Input
If you do not need the Digital Input, disable the Digital Input in the device configuration. In the
delivery state, the Digital Input is disabled.
If you do need the Digital Input
(see on page 39 “Digital Input considerations”)
2.6.6
Disable logical access to unused ports and SFP slots
In the delivery state, all ports and SFP slots are enabled.
Disable network access for unused ports and empty SFP slots: See the user manual
"Configuration", chapter "Configuring the ports". This helps prevent potential attacks that connect
a rogue network device to an unused port.
Note:
Treat inserted SFPs without a data cable the same way as unused ports.
2.6.7
Configure Power over Ethernet
Delivery state:
The device-global setting
PoE Global Operation
is
On
.
Port-related settings:
–
The setting
PoE Port Enable
is
PoE enable
.
–
The allowed classes ,
Class 0
..
Class 4
, are all enabled.
–
The
Power limit [W]
is
0.0
— the device will not enforce a specific power limit.
–
The power PoE
Priority
is
low
.
Device security aspects:
If you do not need PoE or PoE+, disable PoE and PoE+ globally in the device.
If you need PoE or PoE+:
–
Disable PoE or PoE+ on those ports that shall not deliver power.
–
For each port with PoE or PoE+ enabled, configure the minimal necessary reserved power
according to the class (
Class 0
..
Class 4
) of the powered device (PD).
–
If you know the exact power consumption of a PD, additionally set the power limit for the
given port to the known value.
Network availability aspects: Assign a PoE priority (
critical
,
high
, or
low
) to each PoE port. This
helps delivering power to the most important PDs even if the power supply of the device is unable
to deliver its nominal power, for example, if there is a failure.
Summary of Contents for HIRSCHMANN HiOS-2A
Page 6: ...Contents 6 UM Security BRS 2A Release 8 7 05 2022 ...
Page 8: ...Document History 8 UM Security BRS 2A Release 8 7 05 2022 ...
Page 10: ...Safety instructions 10 UM Security BRS 2A Release 8 7 05 2022 ...
Page 54: ...Network security support 3 11 Configure logging 54 UM Security BRS 2A Release 8 7 05 2022 ...
Page 62: ...Index 62 UM Security BRS 2A Release 8 7 05 2022 ...
Page 66: ......