Security
BAT54-Rail/F..
Release
7.54
06/08
7.2
The security checklist
245
U Have you allowed remote access?
If you do not require remote access, deactivate call acceptance by deac-
tivating a call acceptance 'by number' and leaving the number list blank
in LANconfig in the 'Communication' configuration area on the 'Call
accepting' tab.
U Have you activated the callback options for remote
access and is CLI activated?
When a call is placed over an ISDN line, the caller's number is normally
sent over the D channel before a connection is even made (CLI – Calling
Line Identifier). Access to your own network is granted if the call number
appears in the number list, or the caller is called back if the callback
option is activated (this callback via the D channel is not supported by
the Windows Dial-Up Network). If the BAT is set to provide security using
the telephone number, any calls from remote stations with unknown
numbers are denied access.
U Have you activated the Firewall?
The Stateful Inspection Firewall of the BAT ensures that your local net-
work cannot be attacked from the outside . The Firewall can be enabled
in LANconfig under ’Firewall/QoS’ on the register card ’General’.
U Do you make use of a ’Deny All’ Firewall strategy?
For maximum security and control you prevent at first any data transfer
through the Firewall. Only those connections, which are explicitly desired
have to allowed by the a dedicated Firewall rule then. Thus ’Trojans’ and
certain Email viruses loose their communication way back. The Firewall
rules are summarized in LANconfig under ’Firewall/Qos’ on the register
card ’Rules’.