RUGGEDCOM ROX II
CLI User Guide
Chapter 1
Introduction
Available Services by Port 9
mitigates against attacks such as SSL/TLS Protocol Initialization Vector Implementation Information Disclosure
Vulnerability (e.g. BEAST).
• For optimal security, use SNMPv3 whenever possible and apply strong passwords.
• Validate the integrity of the firmware often. This task can be automated by scheduling a job to repeat every day
or week. Firmware integrity can also be checked automatically at start-up.
If an unauthorized/unexpected modification is detected, inspect the syslog for messages related to firmware
integrity to identify which programs and/or files may have been compromised. If remote system logging is
configured, this task can also be automated using scripts to identify key log messages.
For more information about checking the firmware integrity, refer to Section4.13, “Monitoring Firmware
Integrity”.
Policy
• Periodically audit the device to make sure it complies with these recommendations and/or any internal security
policies.
• Review the user documentation for other Siemens products used in coordination with the device for further
security recommendations.
Section1.4
Available Services by Port
The following table lists the services available by the device, including the following information:
• Services
The service supported by the device
• Port Number
The port number associated with the service
• Port Open
The port state, whether it is always open and cannot be closed, or open only, but can be configured
• Port Default
The default state of the port (i.e. open or closed)
• Access Authorized
Denotes whether the ports/services are authenticated during access
Services Port Number Port Open
Port
Default
Access
Authorized
SSH TCP/22 Open (if configured with login) Open Yes
SSH (Service Mode) TCP/222 Open (if configured with login) Closed Yes
NETCONF TCP/830 Open (if configured with login) Open Yes
SFTP TCP/2222 Open (if configured with login) Closed Yes
HTTP TCP/80 Open (if configured with login) Open N/A
NTP UDP/123 Open (if configured) Closed No
SNMP UDP/161 Open (if configured with login) Closed Yes