19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

- To ensure that communications are protected (using MPPE encryption), in<br />

the "Security" tab of Dial-Up Networking, the options "Accept only<br />

Microsoft encrypted authentication" and "Require data encryption" should<br />

be enabled. Care must be taken to ensure that the RAS server is<br />

correspondingly configured.<br />

- Assignment of a fixed IP address to each RAS client should be considered.<br />

This makes it easier to trace activities performed over the RAS connection.<br />

<strong>The</strong> IP address can be entered in the TCP/IP properties of Dial-Up<br />

Networking under Phonebook, Server, TCP/IP Settings in the field<br />

"Specify an IP address".<br />

<strong>The</strong> following applies to RAS servers running under Windows NT:<br />

- RAS dial-in should only be permitted for authorised users. For all other<br />

users, the option "Grant dialin permission to user" must be disabled. This<br />

can be performed either through the User Manager or the RAS Manager.<br />

- <strong>The</strong> option of callback by the RAS server should only be enabled for those<br />

users for whom this is explicitly allowed. If possible, a fixed callback<br />

number should be used.<br />

- In order that RAS clients can request a fixed IP address, the option "Allow<br />

remote clients to request a predetermined IP address" under Control panel,<br />

Network, Services, Remote Access Service, Attached Device, Network,<br />

TCP/IP settings must be enabled.<br />

- If use is to be made of MPPE encryption, then the relevant option must be<br />

enabled. This is achieved by selecting the following sequence of menu<br />

options: Control Panel, Network, Services, Remote Access Service,<br />

Attached Device, Network, Encryption settings.<br />

- It is possible to specify for a RAS server under Windows NT whether RAS<br />

clients should only access the resources of the RAS server or whether they<br />

should be able to access the network to which the RAS server is connected<br />

as well. Depending on the intended purpose (e.g. export of local resources,<br />

RAS access server for a network), the appropriate access restrictions<br />

should be set. This is performed by selecting the option "Allow remote<br />

TCP/IP clients to access" under Control Panel, Network, Services, Remote<br />

Access Server, Attached Device, Network, TCP/IP settings.<br />

Additional controls:<br />

- Are all security breaches identified documented?<br />

- Is user authentication performed for every connection established using the<br />

specified mechanism?<br />

- Is protection of communications enforced for every connection through<br />

one of the procedures permitted in the RAS security concept?<br />

- Can mobile RAS clients be protected through additional safeguards (e.g.<br />

encryption of hard disks)?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!