Alcatel-Lucent Security Management Server (SMS) Installation Manual page 127

Release 9.4
Table of Contents

Advertisement

Port
9091
9092
As an additional recommendation for hardening the operating system, if the use of
multicast packets is not needed on the management platform, disable these functions.
®
For a Sun
Solaris
while logged in as
/usr/sbin/ndd -set /dev/ip ip_respond_to_echo_multicast 0
/usr/sbin/ndd -set /dev/ip ip6_respond_to_echo_multicase 0
/etc/init.d/network restart
Application patches
It is recommended that you install the latest patches for all applications that may be
installed on the operating system. This includes patches to the Alcatel-Lucent SMS and
Remote Navigator products, which are available at the VPN Firewall Product Registration
and Support website, https://vpn-firewall-brick.alcatel-lucent.com
Contact the vendor of your other applications for information about how to obtain the latest
patches and versions.
Password security
User and administrator access to operating system, remote management (such as SNMP),
and applications should be password-enabled using strong password enforcement
mechanisms. The Alcatel-Lucent SMS provides strong password enforcement and it is
recommended that this capability be enabled on this system. Refer to the Using the
Configuration Assistant chapter in the SMS Administration Guide for information on
enabling strong password enforcement.
The Alcatel-Lucent SMS application also includes SNMP-based capabilities to integrate
with network management systems. The SNMP facilities are initially configured to a
standard public community string for access to the SNMP reporting information. While the
SNMP agent that is included in the SMS provides read-only access to information, it is
recommended to also modify the community string to something that meets your strong
password security requirements.
Do the following to modify the Alcatel-Lucent SMS SNMP community string:
1. Log into the Alcatel-Lucent SMS platform as administrator.
2. Bring up the Configuration Assistant.
3. Double-click on the SNMP Agent category.
Service
Type
xmitec-xmimail
TCP
Unknown
TCP
®
-based system, this can be performed using the following commands
:
root
SMS and Operating System Hardening Guidelines
Port Usage
Used in the case of redundant SMS
servers for database synchronization
Used in the case of redundant SMS
servers for database synchronization
...................................................................
115

Advertisement

Table of Contents
loading

This manual is also suitable for:

Security management server 9.4

Table of Contents