© MOBOTIX AG www.mobotix.com
Mx_GL_MOBOTIX_HUB_2021-R1_Hardening-Guide_en_210630.docx • 30.08.2023 • Seite/Page 3/ 94
MOBOTIX HUB – Hardening Guide - Error! Use the Home tab to apply
Inhaltsverzeichnisüberschrift to the text that you want to appear here.
5 DEVICES AND NETWORK .......................................................................................................35
5.1 BASIC STEPS – DEVICES ..........................................................................................................35
5.1.1 USE STRONG PASSWORDS INSTEAD OF DEFAULT PASSWORDS ........................................................................ 35
5.1.2 STOP UNUSED SERVICES AND PROTOCOLS ................................................................................................... 35
5.1.3 CREATE DEDICATED USER ACCOUNTS ON EACH DEVICE .................................................................................. 36
5.1.4 SCANNING FOR DEVICES ............................................................................................................................ 36
5.2 BASIC STEPS – NETWORK ........................................................................................................37
5.2.1 USE SECURE AND TRUSTED NETWORKS CONNECTION .................................................................................... 37
5.2.2 USE FIREWALLS TO LIMIT IP ACCESS TO SERVERS AND COMPUTERS ................................................................. 37
5.2.3 USE A FIREWALL BETWEEN THE VMS AND THE INTERNET ............................................................................... 47
5.2.4 CONNECT THE CAMERA SUBNET TO THE RECORDING SERVER SUBNET ONLY ...................................................... 47
5.3 ADVANCED STEPS – DEVICES ....................................................................................................48
5.3.1 USE SIMPLE NETWORK MANAGEMENT PROTOCOL TO MONITOR EVENTS.......................................................... 48
5.4 ADVANCED STEPS – NETWORK ..................................................................................................48
5.4.1 USE SECURE WIRELESS PROTOCOLS ........................................................................................................... 48
5.4.2 USE PORT-BASED ACCESS CONTROL ........................................................................................................... 48
5.4.3 RUN THE VMS ON A DEDICATED NETWORK .................................................................................................. 49
6 MOBOTIX SERVERS ..............................................................................................................50
6.1 BASIC STEPS – MOBOTIX SERVERS ...........................................................................................50
6.1.1 USE PHYSICAL ACCESS CONTROLS AND MONITOR THE SERVER ROOM ............................................................... 50
6.1.2 USE ENCRYPTED COMMUNICATION CHANNELS ............................................................................................. 50
6.2 ADVANCED STEPS – MOBOTIX SERVERS .....................................................................................50
6.2.1 RUN SERVICES WITH SERVICE ACCOUNTS ..................................................................................................... 50
6.2.2 RUN COMPONENTS ON DEDICATED VIRTUAL OR PHYSICAL SERVERS ................................................................. 51
6.2.3 RESTRICT THE USE OF REMOVABLE MEDIA ON COMPUTERS AND SERVERS ......................................................... 51
6.2.4 USE INDIVIDUAL ADMINISTRATOR ACCOUNTS FOR BETTER AUDITING ............................................................... 51
6.2.5 USE SUBNETS OR VLANS TO LIMIT SERVER ACCESS ...................................................................................... 51
6.2.6 ENABLE ONLY THE PORTS USED BY EVENT SERVER ........................................................................................ 52
6.3 SQL SERVER .......................................................................................................................52
6.3.1 CONNECTION TO THE SQL SERVER AND DATABASE ....................................................................................... 52
6.3.2 RUN THE SQL SERVER AND DATABASE ON A SEPARATE SERVER ...................................................................... 52
6.4 MANAGEMENT SERVER ...........................................................................................................53
6.4.1 ADJUST THE TOKEN TIME-OUT ................................................................................................................... 53
6.4.2 ENABLE ONLY THE PORTS USED BY THE MANAGEMENT SERVER ....................................................................... 53
6.4.3 DISABLE NON-SECURE PROTOCOLS ............................................................................................................ 54
6.4.4 DISABLE LEGACY REMOTING CHANNEL ......................................................................................................... 54
6.4.5 MANAGE IIS HEADER INFORMATION ............................................................................................................ 55
6.4.6 DISABLE IIS HTTP TRACE / TRACK VERBS................................................................................................ 55
6.4.7 DISABLE THE IIS DEFAULT PAGE ................................................................................................................ 56
6.5 RECORDING SERVER ..............................................................................................................56
6.5.1 STORAGE AND RECORDING SETTINGS PROPERTIES ....................................................................................... 56
6.5.2 USE SEPARATE NETWORK INTERFACE CARDS ................................................................................................ 57
6.5.3 HARDEN NETWORK ATTACHED STORAGE (NAS) TO STORE RECORDED MEDIA DATA .......................................... 57
6.6 MOBOTIX MOBILE SERVER COMPONENT .....................................................................................58