Cisco Systems D14659.03 Network Router User Manual


 
Understanding security warnings
Cisco TelePresence ISDN Gateway 2.1 Online help (Printable format) 103 of 135
Unsecured FTP
service is enabled
Disable FTP in network TCP
services
Information sent using FTP is
unencrypted and sent in plain text;
therefore, it is possible for people to
discover usernames and passwords
easily.
To disable FTP, go to Network >
Services and deselect the FTP check
box.
Unsecured HTTP
service is enabled
Disable HTTP in network TCP
services
Information sent using HTTP (Web) is
unsecured and not encrypted.
To disable HTTP, go to Network >
Services and deselect the Web check
box. We recommend that you enable
Secure web.
Unsecured SNMP
service is enabled
Disable SNMP in network UDP
services
Information sent using SNMP is
unencrypted and sent in plain text;
therefore, it is possible for people to
discover usernames and passwords
easily.
To disable SNMP, go to Network >
Services and deselect the SNMP check
box.
Auto-refresh of
web pages is
enabled
Change auto-refresh interval to
"No auto-refresh"
If your ISDN Gateway is set to auto-
refresh it could mean that an unattended
ISDN Gateway will never have a session
timeout.
To turn off auto-refresh, go to Settings >
User interface and change Status page
auto-refresh interval to No auto-refresh.
Audit logging of
configuration
changes is
disabled
Enable the audit log
If the audit log is disabled, the ISDN
Gateway will not create an audit log. To
enable audit logs, go to Logs > Audit log
and select Enable auditing.
For more information on the audit log,
refer to Working with the audit logs.
Audit logs
dropped due to
lack of compact
flash, audit
system integrity
compromised
Check the system configuration
for possible security changes
If no compact flash card is installed in the
ISDN Gateway, logs are only stored up to
a maximum of 200 events. The 200
events do not 'wrap', and therefore when
the maximum is reached the log is
deleted and started over again. To rectify
this problem, insert a compact flash card.
For more information on the audit log,
refer to Working with the audit logs.