User's Manual
Avaya Branch Gateway Manager 10.0 Page 72
15-601011 Issue 29r (Friday, November 02, 2012)B5800 Branch Gateway
10.2. Minimum Security
A minimum security scenario could be where configuration data is open, but the security settings are constrained: Any
individual with the correct service user name and password can access the configuration from any PC installation of
Branch Gateway Manager, no logging of access: Passwords can be simple, and will never age.
· Change all default passwords of all service users and Security Administrator
· Set the system Security Administration service security level to Secure, Low.
· Set the system service user Password Reject Action to None.
· Set the system Client Certificate Checks level to None (default).
· Set the system Minimum Password Complexity to Low (default).
· Set the system Previous Password Limit to zero (default).
· Set the system Password Change Period to zero (default).
· Set the system Account Idle Time to zero (default).
· Set certificate check level to low in Branch Gateway Manager Security Preferences (default).
In addition, any PC installation of Branch Gateway Manager can manage any Avaya Branch Gateway.
10.3. Medium Security
A medium security scenario could be where both configuration and security settings are constrained and a level of
logging is required: Any individual with the correct service user name and password can access the configuration from
any PC installation of Branch Gateway Manager: Passwords cannot be simple, and will age.
· Change all default passwords of all service users and Security Administrator
· Set the system Security Administration service security level to Secure, Medium.
· Set the system Configuration service security level to Secure, Medium.
· Set the system service user Password Reject Action to Log to Audit Trail (default).
· Set the system Client Certificate Checks level to None (default).
· Set the system Minimum Password Complexity to Medium.
· Set the system Previous Password Limit to non zero.
· Set the system Password Change Period to non zero.
· Set the system Account Idle Time to zero (default).
· Disable all the system Unsecured Interfaces.
· Set certificate check level to low in Branch Gateway Manager Security Preferences (default).