13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FIPSPassword guidelinesBelow are general guidelines for defining passwords. To maximize security, it is recommendedto follow <strong>the</strong>se guidelines or use company guidelines where available.●●Password length●●●User password: at least eight charactersO<strong>the</strong>r passwords: at least six charactersPSK (pre-shared keys) for IKE: at least 13 charactersUse a combination <strong>of</strong> upper and lower case letters, numbers and symbols.Note: You●●Note:may use any printable character, such as ?, ! or *Do not use passwords that are easy to guess, such as names, dates, or telephonenumbers.Keep passwords in a safe place.Managing <strong>the</strong> module in FIPS-compliant modeIn FIPS-approved operation mode, all remote configuration activities (Telnet/TFTP/SNMP/FTP)are channeled through a VPN tunnel. The console port is used for local administration.Management through all o<strong>the</strong>r interfaces is disabled. In addition, <strong>the</strong> module will:●●●●●Disable <strong>Administration</strong> over SSH protocol.Disable dial-in via <strong>the</strong> modem ports (serial and USB).Restrict troubleshooting services in <strong>the</strong> production environment by blocking all non-FIPScompliant dev/tech commands, such as tShell.Disable loading and output <strong>of</strong> configuration files from/to <strong>the</strong> SCP server.Allow loading and output <strong>of</strong> configuration files from/to <strong>the</strong> TFTP/FTP server only over aVPN-encrypted tunnel.SECURITY ALERT:! SECURITY ALERT:The “FIPS mode” <strong>of</strong> operation is permanent. If you do not fulfill all <strong>of</strong> <strong>the</strong> steps,you void <strong>Gateway</strong> FIPS-compliant operation. The same happens if, after enteringFIPS mode, you execute an operation that is not consistent with <strong>the</strong>FIPS-approved mode <strong>of</strong> operation. Also note that execution <strong>of</strong> <strong>the</strong> NVRAM Initor zeroize commands clear <strong>the</strong> above defined FIPS-approved modeconfiguration and returns <strong>the</strong> box to factory defaults.306 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!