Security
Polycom, Inc. 141
Scenario 3 - Failed attempts counter resets after failed login window closes
A user fails to log in to the Admin account twice on the web interface, and the same or another user fails to
log in to the Admin account on the local interface.
This means that three failed attempts have been made
to the Admin account so far. If no more failed attempts are made within 1 Hour of the first failed attempt
(which is the value of the Reset Admin Account Lock Counter After setting), the failed login attempts
counter for the Admin account is reset to zero, and 4 failed attempts are allowed again before the Admin
account is locked.
Enable a Whitelist and Add IP Addresses
When a whitelist is enabled, the Polycom RealPresence Group system web interface and SNMP ports
accept connections only from specified IP addresses. The whitelist supports both IPv4 and IPv6 addresses.
You can only configure this feature in the web interface.
To enable a whitelist:
1 In the web interface, go to Admin Settings > Security > Global Security > Access.
2 Select Enable Whitelist.
To add addresses to an enabled whitelist:
1 Click the Edit Whitelist link.
2 Select address type IPv4 or IPv6.
3 In the address text field, enter the IP address of the system you want to allow. Follow the format
suggested by the address type you selected. Select Add.
Repeat this step for all the IP addresses you want to add. You can add web server and SNMP
addresses.
If you entered an address in error, highlight the address in the list and select Clear.
IPv4 Address Formats
The whitelist configuration requires single IP addresses, a range of addresses, or an IP and netmask. The
netmask represents the number of valid bits of the IPv4 address to use. The following are valid IPv4 formats:
● 10.12.128.7
● 172.26.16.0/24
IPv6 Address Formats
For IPv6 addresses, you can use Classless Inter-Domain Routing (CIDR) notation to represent a range of
IP addresses. The following are valid IPv6 formats:
● ::1
Note: Update whitelist if you have dynamic IP address
If you use dynamic IP address assignment, ensure that you keep the whitelist up to date with the
latest assigned addresses for computers authorized to access the system. Failing to update the
whitelist means these computers cannot connect to the system.