Port Lockout - Polycom realpresence group series Administrator's Manual

Hide thumbs Also See for realpresence group series:
Table of Contents

Advertisement

● 2001:db8:abc:def:10.242.12.23
● 2001:db8::/48
● 2001:db8:abcd:0012::0/64
● 2001:0db8:85a3:0000:0000:1234:0abc:cdef
Note: Whitelist limit
The system can accept up to 30 IP address entries for the whitelist.

Port Lockout

Port lockout protects against brute-force attacks by temporarily locking the login port after a configurable
number of unsuccessful login attempts have been made, regardless of which account was used. It is
supported only on the web interface.
Note: Telnet port lockout
The telnet port has a port lock feature that is enabled regardless of the state of the port lock feature
configuration. Specifically, the telnet server disconnects a telnet login session after 5 failed login
attempts. If a new session is started, another 5 attempts are allowed.
To configure the port lockout feature:
1 In the web interface, go to Admin Settings > Security > Global Security > Access.
2 Configure these settings and click Save.
Setting
Lock Port after Failed Logins
Port Lock Duration
Reset Port Lock Counter After
Port lockout is supported only on the web interface, and only Admin users are allowed to log in to the web
interface. If external authentication is not in use, users can successfully log in to the web interface only by
using the local Admin account credentials. However, when external authentication is in use, any number of
external accounts can be considered to be Admin users on the system. Failed logins to any of these
accounts, or to an unknown account, are all counted against the configured number allowed failed login
attempts to the web interface.
Polycom, Inc.
Description
Specifies the number of failed login attempts allowed before the system locks
the web interface from accepting logins. If set to Off, the system does not
lock the web interface due to failed login attempts.
Specifies the amount of time that a web interface remains locked due to failed
login attempts. After this time period expires, the failed login attempts counter
is reset to zero and logins to the web interface are once again allowed.
Specifies a "failed login window" period of time, starting with the first failed
login attempt, during which subsequent failed login attempts will be counted
against the maximum number allowed (Lock Port after Failed Logins). If the
number of failed login attempts made during this window does not reach the
maximum number allowed, the failed login attempts counter is reset to zero at
the end of this window.
Note: The failed login attempts counter is always reset to zero anytime a user
successfully logs in.
Security
142

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents