19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

that a password that is necessary for authentication can be transmitted to the<br />

server without being encrypted. This favours unauthorised infiltration into the<br />

system concerned. <strong>The</strong> default value of OFF ensures that each password has to<br />

be encrypted during the login procedure. Unencrypted passwords are not<br />

accepted.<br />

SET ALLOW AUD<strong>IT</strong> PASSWORDS = OFF (Default=OFF)<br />

This parameter is connected to the auditing mechanisms of the Netware<br />

operating system. During auditing, changes to (or manipulations of) objects<br />

are recorded in accordance with the specifications of the configurations by<br />

means of the AUD<strong>IT</strong>CON.NLM program. Given the appropriate<br />

authorisations, which can be set individually for each auditor in the general<br />

assignment of rights for the operating system, an auditor can be put in a<br />

position to read the auditing file. <strong>The</strong> authorisation in each case restricts the<br />

scope of what can be read. <strong>The</strong> effect of the default value OFF is that the<br />

auditor does not have to identify himself with an additional password.<br />

SET AUTOMATICALLY REPAIR BAD VOLUMES = ON (Default=ON)<br />

This parameter instructs the operating system to repair a volume that cannot<br />

be mounted on system startup by invoking the VREPAIR.NLM program. This<br />

ensures that after an uncontrolled system crash and the subsequent restart,<br />

possible errors on volumes (data areas in the disk packs) will be rectified<br />

without additional intervention by the system administrator.<br />

SET REJECT NCP PACKETS W<strong>IT</strong>H BAD LENGTHS = ON (Default=OFF)<br />

<strong>The</strong> effect of this parameter when set to ON is that NCP packets with the<br />

incorrect length will be rejected. This may lead to errors with older<br />

applications (utilities).<br />

SET REJECT NCP PACKETS W<strong>IT</strong>H BAD COMPONENTS = ON<br />

(Default=OFF)<br />

<strong>The</strong> effect of this parameter when set to ON is that NCP packets with incorrect<br />

components will be rejected. In this case, too, there may be errors with older<br />

applications (utilities).<br />

SET IPX NETBIOS REPLICATION OPTION = 0 (Default=2)<br />

This parameter specifies the procedures that the IPX router is to use for<br />

dealing with NetBIOS broadcast messages. <strong>The</strong> following values are available<br />

for selection:<br />

0 = No replication of type 20 IPX packets<br />

1 = Replication of type 20 IPX packets to all available network adapters<br />

2 = Replication of type 20 IPX packets with two special filter functions<br />

a) Reverse Path Forwarding: type 20 IPX packets from the same<br />

source are forwarded only once to all available network cards, even<br />

if the packets have been received via different network adapters.<br />

b) Split Horizon: type 20 IPX packets are not routed back into the<br />

network from which they were received.<br />

3 = Replication as for option 2, but not via long-distance links<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!