121
Security
This section outlines security issues related to the Media Application Server
(MAS) and the associated services.
The security issues include:
•
"Microsoft IP filter and Microsoft ports" (page 121)
•
"Media Application Server ports" (page 122)
•
"Media Application Server security" (page 123)
Microsoft IP filter and Microsoft ports
All MAS-based applications are deployed on the Microsoft Windows 2000
Server operating system. The installed system image is hardened for
security reasons. Known vulnerability points are addressed by either
removing vulnerable services or by using IP filtering in the operating system
to prevent outside access to potentially exploitable services like Microsoft
Remote Procedure Call (RPC). All security fixes contained in Service Pack
4 for Windows 2000 are present. Service Pack 4 is included in the default
image installed on all servers hosting MAS applications.
The IP filter is preconfigured to allow inbound connections to the server on
only one Microsoft port (3389). Microsoft port 3389 is used for Microsoft
Terminal Services (see
Table 32 "Microsoft open ports in TCP/IP Filter"
(page 121)
). All other ports are closed.
Table 32
Microsoft open ports in TCP/IP Filter
Port number
Description
3389
Microsoft Terminal Services
Nortel Media Application Server
Media Application Server Planning and Engineering
NN42020-201
01.04
Standard
4.0
27 July 2007
Copyright © 2007, Nortel Networks
.