background image

10

Netra Blade X3-2B Security Guide • November 2012

Hardware Power Control

You can use software to turn on and off power to some Oracle systems. The power
distribution units (PDUs) for some system cabinets can be enabled and disabled
remotely. Authorization for these commands is typically set up during system
configuration and is usually limited to system administrators and service personnel.

See your system or cabinet documentation for further information.

Asset Tracking

Use serial numbers to track inventory. Oracle embeds serial numbers in firmware on
option cards and system mother boards. You can read these serial numbers through
local area network connections.

You can also use wireless radio frequency identification (RFID) readers to further
simplify asset tracking. An Oracle white paper,How to Track Your Oracle Sun System
Assets by Using RFID is available at:

http://www.oracle.com/technetwork/articles/systems-hardware-arch

itecture/o11-001-rfid-oracle-214567.pdf

Maintaining Updates for Software and
Firmware

Keep your software and firmware versions current on your server equipment.

Check regularly for updates.

Always install the latest released version of the software or firmware on your
equipment.

Install any necessary security patches for your software.

Devices such as network switches, and ExpressModules also contain firmware and
might require patches and firmware updates.

Summary of Contents for Netra X6270 M3

Page 1: ...Netra Blade X3 2B formerly Sun Netra X6270 M3 Server Module Security Guide Part No E26849 04 November 2012 ...

Page 2: ... concédés sous licence et soumis à des restrictions d utilisation et de divulgation Sauf disposition de votre contrat de licence ou de la loi vous ne pouvez pas copier reproduire traduire diffuser modifier breveter transmettre distribuer exposer exécuter publier ou afficher le logiciel même partiellement sous quelque forme et par quelque procédé que ce soit Par ailleurs il est interdit de procéder...

Page 3: ... 3 Restrict Access 3 Record Serial Numbers 4 Software Security 4 Oracle ILOM Firmware 5 Operating System Security Guidelines 5 Oracle System Assistant Security Information 5 Understanding that OSA Contains a Bootable Root Environment 6 Understanding that OSA Mounts a USB Storage Device Accessible to the OS 6 Disabling OSA 6 Maintaining a Secure Environment 9 Oracle ILOM Security 9 ...

Page 4: ...4 Netra Blade X3 2B Security Guide November 2012 Hardware Power Control 10 Asset Tracking 10 Maintaining Updates for Software and Firmware 10 Local and Remote Access 11 Data Security 12 ...

Page 5: ...The Sun Blade X6270 M3 server module is based on two Intel R Xeon R processors in the E5 2600 family and the Intel C600 series chipset The Sun Blade X6270 M3 server module includes an on board Oracle ILOM service processor SP Basic Security Principles There are four basic security principles access authentication authorization and accounting Access Use physical and software controls to protect you...

Page 6: ...Write Execute permissions to control user access to commands disk space devices and applications Accounting Customer IT personnel can use Oracle software and hardware features to monitor login activity and maintain hardware inventories Use system logs to monitor user logins In particular track System Administrator and Service accounts through system logs because these accounts can access powerful ...

Page 7: ...n be secured fairly simply limit access to the hardware and record serial numbers The following topics are covered Restrict Access on page 3 Record Serial Numbers on page 4 Restrict Access Install servers and related equipment in a locked restricted access room If equipment is installed in a rack with a locking door keep the door locked except when you have to service components in the rack Lock t...

Page 8: ...ange all default passwords when installing a new system Most types of equipment use default passwords such as changeme that are widely known and would allow unauthorized access to the equipment Change every password on network switches which might have multiple user accounts and passwords by default Limit use of the root superuser account Oracle Integrated Lights Out Manager Oracle ILOM accounts s...

Page 9: ...s Out Manager Oracle ILOM documentation http www oracle com pls topic lookup ctx ilom31 Operating System Security Guidelines Oracle System Assistant Security Information The following post installation topics are covered Understanding that OSA Contains a Bootable Root Environment on page 6 Operating System Link Oracle Solaris OS http docs oracle com cd E23824_01 html 819 31 95 index html Oracle Li...

Page 10: ...oot shell users of OSA from being able to read disk contents Understanding that OSA Mounts a USB Storage Device Accessible to the OS In addition to being a bootable environment Oracle System Assistant is also mounted as a USB storage device accessible to the host operating system after installation This is useful in accessing tools and drivers for maintenance and reconfiguration The OSA flash devi...

Page 11: ...rom BIOS Once disabled it can only be re enabled from BIOS Setup It is recommended that BIOS Setup be password protected such that only authorized users can re enable OSA See the Oracle System Assistant documentation for instructions on how to disable OSA or refer to the Netra Blade X3 2B Administration Guide ...

Page 12: ...8 Netra Blade X3 2B Security Guide November 2012 ...

Page 13: ...ILOM Security on page 9 Hardware Power Control on page 10 Asset Tracking on page 10 Maintaining Updates for Software and Firmware on page 10 Local and Remote Access on page 11 Data Security on page 12 Oracle ILOM Security Refer to the Oracle ILOMSecurity Guide for further information on Oracle Integrated Lights OutManager Oracle ILOM For general Oracle ILOM information refer to http www oracle com...

Page 14: ...You can read these serial numbers through local area network connections You can also use wireless radio frequency identification RFID readers to further simplify asset tracking An Oracle white paper How to Track Your Oracle Sun System Assets by Using RFID is available at http www oracle com technetwork articles systems hardware arch itecture o11 001 rfid oracle 214567 pdf Maintaining Updates for ...

Page 15: ... switch for intrusion detection system IDS access Implement port security to limit access based upon aMAC address Disable autotrunking on all ports Limit remote configuration to specific IP addresses using SSH instead of Telnet Telnet passes user names and passwords in clear text potentially allowing everyone on the LAN segment to see login credentials Set a strong password for SSH Early versions ...

Page 16: ... Use data encryption software to keep confidential information on hard drives secure Data destruction When disposing of an old hard drive physically destroy the drive or completely erase all the data on the drive Deleting all the files or reformatting the drive will remove only the address tables on the drive information can still be recovered from a drive after deleting files or reformatting the ...

Reviews: