47
Placing Digital iPEPS alongside the firewall
Digital iPEPS is built from the ground-up to be secure. It employs a sophisticated
128bit public/private key system that has been rigorously analysed and found
to be highly secure (a security white paper is available upon request from
Adder Technology Ltd). Therefore, you can position the Digital iPEPS alongside
the firewall and control a computer that is also IP connected within the local
network.
IMPORTANT: If you make the Digital iPEPS accessible from the public Internet,
care should be taken to ensure that the maximum security available is activated.
You are strongly advised to enable encryption and use a strong password.
Security may be further improved by restricting client IP addresses, using a non-
standard port number for access.
Ensuring sufficient security
The security capabilities offered by the Digital iPEPS are only truly effective when
they are correctly used. An open or weak password or unencrypted link can
cause security loopholes and opportunities for potential intruders. For network
links in general and direct Internet connections in particular, you should carefully
consider and implement the following:
• Ensurethatencryption is enabled.
• Ensurethatyouhaveselectedsecure passwords with at least 8 characters
and a mixture of upper and lower case and numeric characters.
• Reservetheadminpasswordforadministrationuseonlyanduseanon-
admin user profile for day-to-day access.
• UsethelatestSecureVNCviewer(thishasmorein-builtsecuritythanis
availablewiththeJavaviewer).
• Usenon-standardport numbers.
• RestricttherangeofIPaddressesthatareallowedtoaccesstheDigitaliPEPS
to only those that you will need to use. To restrict IP access.
• DoNOTForceVNCprotocol3.3.
• EnsurethatthecomputeraccessingtheDigitaliPEPSiscleanofvirusesand
spyware and has up-to-date firewall and anti-virus software loaded that is
appropriately configured.
• AvoidaccessingtheDigitaliPEPSfrompubliccomputers.
Security can be further improved by using the following suggestions:
• PlacetheDigitaliPEPSbehindarewallanduseportthenumberstoroute
the VNC network traffic to an internal IP address.
• Reviewtheactivitylogfromtimetotimetocheckforunauthoriseduse.
• Lockyourserverconsolesaftertheyhavebeenused.
A security white paper that gives further details is available upon request from
Adder Technology Limited.
Ports
In this configuration there should be no constraints on the port numbers
because the Digital iPEPS will probably be the only device at that IP address.
Therefore, maintain the HTTP port as 80 and the VNC port as 5900.
Addressing
When the Digital iPEPS is situated alongside the firewall, it will require a public
static IP address (i.e. one provided by your Internet service provider).
More addressing information:
Discover DHCP-allocated addresses
DNS addressing