Security Hardening for OS and Web Portal
From TBwiki
(Difference between revisions)
William Wong (Talk | contribs) (→Management Port Protection) |
William Wong (Talk | contribs) (→SSH Access Security) |
||
Line 22: | Line 22: | ||
== SSH Access Security == | == SSH Access Security == | ||
− | Use a strong password for the SSH access. Default password is quite a strong password that including alpanumerical and symbol characters, | + | Use a strong password for the SSH access. Default password is quite a strong password that including alpanumerical and symbol characters, in lengthly number. See [[How to change host password on Linux]] |
== CentOS Update for New Packages == | == CentOS Update for New Packages == |
Revision as of 23:57, 23 July 2017
Contents |
Applicable Products
- TMG800, TMG3200, TMG7800-CTRL
- TSG800, TSG3200
- Tdev Linux server with (CentOS, RedHat, etc) running Toolpack software
- TSBC-SW/TSBC-HW-SRV-HIGH/TSBC-HW-SRV-MID
- TSBC5000
Introduction
This page discusses methods for improving overall security of Telcobridges system against unwanted attacks and vulnerabilities with adverse exposure as introduced from internet or connecting to network in general.
Tmedia/Tsig/Tdev
Management Port Protection
- Keep the management port in a protected environment (behind a firewall). See Firewall. Note that Mysql port 3306 is for internal use only, this should not be allowed for external access.
- Iptables could be used to set up rules for management interface to allow only necessary protocols and ports required for access and operation of Telcobridges system.
- Other ports do not have access to the OS (unless configured on the web portal). Normally, other ports on the system are configured with services other than management such as OAMP/NAT or FIXED MANAGEMENT.
- For example, Voip0 is configured with SIP and RTP, and this port will care for these specific protocols only and discard the rest of the traffic.
- For configuring port IP interface setting and services, see example of VOIP port IP interface configuration and Services to use.
- In normal operation, only default Mgmt port, or a dedicated Ethernet port on external host server, should be used for management access. SIP/RTP/SIGTRAN or RADIUS/H248 together or separate, could be used on voip0/voip1/eth0/eth1.
SSH Access Security
Use a strong password for the SSH access. Default password is quite a strong password that including alpanumerical and symbol characters, in lengthly number. See How to change host password on Linux
CentOS Update for New Packages
- Keep system CentOS with database /and Ruby up to date as needed, using yum update or through web portal by doing upgrade linux packages, see Upgrade CentOS.
- Telcobridges has adopted a proactive OS update practice and managing Telcobridges repository according to CentOS annoucement.
- Also, on January 27, 2015, a vulnerability named "GHOST" in the glibc library was publicly announced. GHOST is also referred as CVE-2015-0235. The vulnerability is a buffer overflow in the gethostbyname family of functions that can allow arbitrary code execution. See GHOST for details on what is affected and update procedure of CentOS 5 from Telcobridges repository.
Web Portal Access Security
- One or more user groups can be created to define access rights, such as read only, read/write, or no access at all. Access rights can be assigned to all regions of the web portal or to specific areas. One or more users can be created and given access, which was previously defined by user groups. A user is given a name, a password, and assigned to a user group.
- HTTPS is available from 2.9.41 and onwards. HTTPS provides a secure connection between browser and web server. The connection is encrypted using TLS/SSL.
- Web Portal access security enhancement is available on Toolpack 2.10.19 and onwards
- After a web portal failed login access, it will wait about 2 seconds, to prevent brute force attack on web portal login
- There will be new password complexity requirements such as,
- At least 8 characters total
- At least 1 upper case character
- At least 1 lower case character
- At least 1 number
- At least 1 special character
- User account disabling (there will be a check box to indicate active users account), uncheck it will disable the account
- Password confirmation when creating/editing users
- Web session auto-logout after a certain amount of time without activity (default 30 mins)
- See System Settings 2.10
Tsbc
- TSBC products follow all the security hardening practices for SSH Access Security, CentOS Update for New Packages, and Web Portal Access Security (see Tsbc System Settings 3.0) of Tmedia/Tsig/Tdev above.
- For TSBC, web portal (all host interfaces), ssh (when enabled and managed by web), SNMP service (all host interfaces) are firewall protected through tbrouter within TSBC.
- Web portal/SSH access ports refer to those LAN/WAN ports that have sevice defined for management such as OAMP/NAT or FIXED MANAGEMENT
- TSBC's physical management port (mgmt) should be used for serial connection at all times.