Veritas Access Appliance 8.4 Initial Configuration Guide
- Getting to know the Access Appliance
- Preparing to configure the appliance
- Configuring the appliance for the first time
- Getting started with the Veritas Access GUI
- Network connection management
- Resetting the appliance to factory settings
- Appliance security
- About Access appliance user account privileges
- About the Access Appliance intrusion detection system
- About Access appliance operating system security
- Recommended IPMI settings on the Access appliance
Recommended IPMI settings on the Access appliance
Review this section to ensure that the Veritas Remote Management Console and the IPMI port are secure.
Do not allow accounts with null user name or password.
It is recommended to have one administrative user.
It is recommended to disable the anonymous user.
To mitigate the CVE-2013-4786 vulnerability:
Use strong passwords to limit the effectiveness of offline dictionary attacks and brute force attacks. The recommended password length is 16-20 characters.
Use Access Control Lists (ACLs) or isolated networks to limit access to the IPMI interface.
Table: Login security settings
Settings | Recommended values |
---|---|
Failed login attempts | 3 |
User Lockout time (min) | 60 seconds |
Force HTTPS | Yes The Force HTTPS check-box must be enabled to ensure that the IPMI connection always takes place over HTTPS. |
Web Session Timeout | 1800 |
Veritas recommends that you should enable LDAP authentication, if possible in your environment.
Veritas recommends that you import a new or custom SSL certificate.
Table: Remote session security settings
Settings | Recommended values |
---|---|
KVM Encryption | AES |
Media Encryption | Enable |
Do not set cipher to zero on the IPMI channel
Warning:
If the cipher 0 enabled on a channel, it allows anyone to perform any IPMI action with no authentication, effectively subverting IPMI security entirely. Disable it at all costs.
Only use ciphers 3, 8, and 12.
Recommended to have a dedicated Ethernet connection for IPMI, that is you should avoid sharing the server's physical connection.
Use a static IP
Avoid DHCP