MDS 05-6632A01, Rev. F MDS Orbit MCR/ECR Technical Manual 43
Figure 3-11. User Password Initial Setup Wizard Change Screen
The selected password(s) must follow the rules established on the “Password Options” screen located
under the Basic Config tab of the User Authentication section. These rules may be modified to conform
to the local security requirements.
Security Review 3.1.4
The Orbit MCR provides strong cyber security capabilities that may be customized to meet enterprise
security policy requirements. By default the Orbit MCR is configured with a light level of security. There
are many features and parameters that should be considered and adjusted according to the security policy.
Some of the areas to consider are:
User Authentication 1.
- Update factory default passwords.
- Secure login access into Orbit with local or RADIUS based user authentication.
Device Management 2.
- Secure access to Orbit for device management by enabling/disabling HTTP/HTTPS/SSH.
- It is recommended that HTTP be disabled.
- It is recommended that SNMPv1/v2c be disabled and SNMPv3 be enabled
Static Routing - Limit local broadcast and multicast traffic from being shared with specified 3.
interfaces.
Packet Filtering – Prevent ingress/egress of unwanted traffic by configuring firewall/NAT. 4.
Secure end-to-end network links using IPsec VPN with pre-shared-key or certificate based setup. 5.
Cellular Security – Utilize IPSec VPN to secure end-to-end cellular link over public cellular 6.
networks.
WiFi Security – Secure Wi-Fi link with pre-shared key or EAP-TLS/RADIUS using certificates. 7.
NX915 Security – Secure 900MHz link pre-shared key or EAP-TLS/RADIUS using certificates. 8.