User guide
23
Placing AdderLink IP Gold alongside the firewall
AdderLink IP Gold is built from the ground-up to be secure. It employs a
sophisticated 128bit public/private key system that has been rigorously analysed
and found to be highly secure (a security white paper is available upon request
from Adder Technology Ltd). Therefore, you can position the AdderLink IP Gold
alongside the firewall and control hosts that are also IP connected within the
local network.
IMPORTANT: If you make the AdderLink IP Gold accessible from the public
Internet or from a modem, care should be taken to ensure that the maximum
security available is activated. You are strongly advised to enable encryption and
use a strong password. Security may be further improved by restricting client
IP addresses, using a non-standard port number for access or limiting remote
access to dial up connections only.
Ensuring sufficient security
The security capabilities offered by the AdderLink IP Gold are only truly effective
when they are correctly used. An open or weak password or unencrypted link
can cause security loopholes and opportunities for potential intruders. For
network links in general and direct Internet connections in particular, you should
carefully consider and implement the following:
• Ensurethatencryptionisenabled.
By local configuration or by remote configuration.
• Ensurethatyouhaveselectedsecurepasswordswithatleast8characters
and a mixture of upper and lower case and numeric characters.
By remote configuration.
• Reservetheadminpasswordforadministrationuseonlyanduseanon-
admin user profile for day-to-day access.
• UsethelatestSecureVNCviewer(thishasmorein-builtsecuritythanis
available with the Java viewer). To download the viewer.
• Usenon-standardport numbers.
• RestricttherangeofIPaddressesthatareallowedtoaccesstheAdderLinkIP
Gold to only those that you will need to use. To restrict IP access.
• DoNOTForceVNCprotocol3.3.Remote configuration. Protocol 3.3 is a
legacy version that does not offer any encryption.
• Addafurtherlevelofinherentsecuritybyrestrictingaccessonlyviamodem
or ISDN dialup.
• EnsurethatthecomputeraccessingtheAdderLinkIPGoldiscleanofviruses
and spyware and has up-to-date firewall and anti-virus software loaded that
is appropriately configured.
• AvoidaccessingtheAdderLinkfrompubliccomputers.
Security can be further improved by using the following suggestions:
• UseaKVMswitchwithOn-Screen-Displaydrivensecurityaccessandan
auto-logout (after inactivity) feature to provide a second level of security. KVM
switches such as the AdderView Matrix or SmartView XPro are recommended.
• PlacetheAdderLinkIPGoldbehindarewallanduseportthenumbersto
route the VNC network traffic to an internal IP address.
• Reviewtheactivitylogfromtimetotimetocheckforunauthorizeduse.
• Lockyourserverconsolesaftertheyhavebeenused.
A security white paper that gives further details is available upon request from
Adder Technology Limited.
Ports
In this configuration there should be no constraints on the port numbers
because the AdderLink IP Gold will probably be the only device at that IP
address.Therefore,maintaintheHTTPportas80andtheVNCportas5900.
Addressing
When the AdderLink IP Gold is situated alongside the firewall, it will require a
public static IP address (i.e. one provided by your Internet service provider).
More addressing information:
Discover DHCP-allocated addresses
DNS addressing