Advanced security
The
Advanced security
page (
Maintenance > Advanced security
) is used to configure the VCS for use in
highly secure environments. This page can only be accessed if the
Advanced Account Security
option key
is installed.
You can configure the system for:
n
Advanced account security mode
n
FIPS140-2 cryptographic mode
Configuring advanced account security mode
Enabling advanced account security limits login access to remotely authenticated users using the web
interface only, and also restricts access to some system features. To indicate that the VCS is in advanced
account security mode, any text specified as the
Classification banner
message is displayed on every web
page.
Note that a system reboot is required for changes to the advanced account security mode to take effect.
Prerequisites
Before advanced account security mode can be enabled:
n
the system must be configured to use
remote account authentication
for administrator accounts
n
the
Advanced Account Security
option key must be installed
CAUTION
:
ensure that the remote directory service is working properly, as after advanced account security
is enabled you will not be able to log in to the VCS via the local
admin
account or as
root
.
You are also recommended to configure your system so that:
n
SNMP
is disabled
n
the
session time out period
is set to a non-zero value
n
HTTPS client certificate validation
is enabled
n
user account LDAP server
configuration uses TLS encryption and has certificate revocation list (CRL)
checking set to
All
n
remote logging
is disabled
n
incident reporting
is disabled
n
any connection to an
external manager
uses HTTPS and has certificate checking enabled
Alarms are raised for any non-recommended configuration settings.
Enabling advanced account security
To enable advanced account security:
1. Go to
Maintenance > Advanced security
.
2. Enter a
Classification banner
.
The text entered here is displayed on every web page.
Cisco VCS Administrator Guide (X8.1.1)
Page 295 of 507
Maintenance
Advanced security