
• Select a Security Profile, which defines:
• Enabled services (FTP, ICMP, IPSec and Telnet)
• SSH and HTTP/HTTPS access
• Enable or disable Bootp Configuration retrieval
The administrator can select either a preconfigured Security Profile or create a custom profile.
All the services and the SSH and HTTP/HTTPS configuration options that are enabled and disabled for each
Security Profile are shown in the Wizard - Security and the System - Security - Security Profile pages.
To configure a Security Profile:
1. Select System - Security - Security Profile.
2. In the Idle Timeout field, enter the number of minutes before the console server times out open sessions.
NOTE: This value applies to any user session to the appliance via HTTP, HTTPS, SSH, Telnet or CONSOLE port. It will not overwrite
the value configured for the user's authorization group. The new idle time-out will be applied to new sessions only.
3. Under the Enabled Services section, enable or disable the RCP checkbox.
4. Under the Serial Devices heading, enable or disable the Port access is controlled by authorizations assigned
to user groups checkbox.
5. Under Bootp Configuration retrieval, enable or disable the service.
6. Select the checkbox for Custom, Moderate, Open or Secure under the Security Profile heading.
7. Click Save.
DSView 3 software security
You can also configure DSView 3 software security settings. When the console server is managed by the
DSView 3 software, the DSView 3 server will supply the certificate to the console server. Under normal
conditions, the DSView 3 software will manage the certificate to clear and replace it with a new certificate as
needed. If communication with the DSView 3 software is lost, the DSView server will be unable to clear the
certificate and the console server cannot be used. Click the Clear DSView Certificate button to configure the
console server in Trust All mode.
To configure DSView 3 software security settings:
1. Select System - Security - DSView.
2. Click the Allow appliance to be managed by DSView checkbox and click Save.
FIPS module
The console server has embedded the FIPS-capable OpenSSL that is the combination of the FIPS Object Module
(the FIPS 140-2 validated module) along with a FIPS-compatible OpenSSL (it is a version of the OpenSSL
product that is designed for compatibility with the FIPS Object Module API).
If an administrator enables the FIPS module, the console server will use the FIPS Object Module to perform
encryption operations. The FIPS module is disabled by default.
Chapter 3: Accessing the Console Server via the Web Manager 19
Comentarios a estos manuales