Lantronix SCS100/200/400 SCS100 / SCS200 / SCS400 - User Guide - Page 49

Security Enhancements, Com Port Redirector, Incoming Security, Port User Restrictions

Page 49 highlights

SCS100/200/400 User Guide 6: Application Setup Security Enhancements This section describes methods for increasing the security of the SCS. Incoming Security You can make the SCS into a highly secure host by turning off the FTP and HTTP services using the command: Set/Define Proto [ HTTP | FTP ] [Enabled | Disabled] Note: The web interface will no longer be available. You can further restrict access to only SSH connections to the SCS command line and serial ports, using the following command: Set/Define Server Incoming Secure The Server Incoming Secure command disallows unsecure Telnet and TCP connection attempts. Access is through SSH only. Port User Restrictions To reject network connections to ports not on a user's port target list, use the command: Set/Define Authentication User Port Target To reject serial logins to ports not on a user's port list, use the command: Set/Define Authentication User Port Serial To show the user's current port restrictions, use the command: Show Authentication User To reset the permissions back to the default, use the command: Set/Define Authentication User Port Factory Com Port Redirector The Com Port Redirector application allows Microsoft Windows-based PCs to access modems or other serial devices connected to a Secure Console Server as if those serial devices were local Com ports. The Redirector creates virtual com ports and intercepts communications from existing device software, then redirects those communications over the IP network to the serial ports on your SCS. The Com Port Redirector works in the background. The Com Port Redirector software and installation instructions are included on the distribution CD-ROM or from the Lantronix web site at: ftp://ftp.lantronix.com/pub/redirector 6-20

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61

SCS100/200/400 User Guide
6: Application Setup
Security Enhancements
This section describes methods for increasing the security of the SCS.
Incoming Security
You can make the SCS into a highly secure host by turning off the FTP and HTTP
services using the command:
Set/Define Proto [ HTTP | FTP ] [Enabled | Disabled]
Note:
The web interface will no longer be available.
You can further restrict access to only SSH connections to the SCS command line and
serial ports, using the following command:
Set/Define Server Incoming Secure
The
Server Incoming Secure
command disallows unsecure Telnet and TCP connection
attempts. Access is through SSH only.
Port User Restrictions
To reject network connections to ports not on a user’s port target list, use the command:
Set/Define Authentication User <username> Port Target <portlist>
To reject serial logins to ports not on a user’s port list, use the command:
Set/Define Authentication User <username> Port Serial <portlist>
To show the user's current port restrictions, use the command:
Show Authentication User
<username>
To reset the permissions back to the default, use the command:
Set/Define Authentication User <username> Port Factory
Com Port Redirector
The Com Port Redirector application allows Microsoft Windows-based PCs to access
modems or other serial devices connected to a Secure Console Server as if those serial
devices were local Com ports. The Redirector creates virtual com ports and intercepts
communications from existing device software, then redirects those communications over
the IP network to the serial ports on your SCS. The Com Port Redirector works in the
background.
The Com Port Redirector software and installation instructions are included on the
distribution CD-ROM or from the Lantronix web site at:
6-20