19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.41 Secure configuration of remote access under<br />

Windows NT<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

Users can connect to local Windows NT systems from remote <strong>IT</strong> systems via<br />

RAS (Remote Access Service). For this, the RAS-client must be installed on<br />

the remote <strong>IT</strong> system and the RAS-server on the local <strong>IT</strong> system which<br />

accepts the remote connection. Using RAS, these users can work as if they<br />

were directly connected to the network. <strong>The</strong> remote clients use standard<br />

programmes to access resources. With the help of the File-Manager or<br />

Explorer, network drives and printers are, for example, connected. <strong>The</strong>se<br />

connections are permanent, i.e. users do not have to recreate connections to<br />

network resources during one session. As clients, the systems Windows NT,<br />

Windows 95, WfW, MS-DOS and OS/2 are supported.<br />

<strong>The</strong> user creates the connection to the RAS-server with a local modem, X.25<br />

or ISDN-card. <strong>The</strong> RAS-server, which is run on the Windows NT server,<br />

authenticates and serves the user until either he or the administrator terminates<br />

the session. <strong>The</strong> RAS connection provides all the services (file and printer<br />

sharing, database access and notifications) that are normally available to a user<br />

connected via a LAN.<br />

Access to the RAS is provided for the whole pool of Windows NT user<br />

accounts. With the User-Manager, permission to dial in to the local network<br />

can be provided to single users, user groups or all users. Furthermore, RAS<br />

administration offers an option which allows access either to all resources<br />

which the RAS host can access within the network, or only to the resources<br />

available on the local computer. <strong>The</strong> users then use their domain log-on to<br />

create a connection via RAS. Once the user's access permission has been<br />

checked by the RAS, he can use the local resources or, if he has been granted<br />

the appropriate permission, the resources in the whole domain as well as in<br />

trusted domains.<br />

Via the Challenge Handshake Authentication Protocol (CHAP) the Remote<br />

Access Server provides the securest form of encrypted access permission<br />

which is supported by the server as well as the client. CHAP allows the RAS<br />

server to systematically make a selection from the securest encryption<br />

mechanism to the most insecure procedure of plain-text transmission and it<br />

protects transmitted passwords in the process.<br />

CHAP allows the employment of diverse encryption algorithms. RAS in<br />

particular uses the cryptographic algorithm MD5. RAS refers to DES<br />

encryption for authentication if the client and the server work with RAS. For<br />

data communication, Windows NT, Windows for Workgroups and Windows<br />

95 select among themselves the DES encrypted confirmation of authenticity.<br />

When connecting to external RAS servers or client software, a confirmation of<br />

authenticity is possible with SPAP or unencrypted text, if the external product<br />

does not support an encrypted confirmation of authenticity.<br />

MD5, an encryption scheme installed by diverse PPP implementations for<br />

encrypted confirmations of authenticity, can be selected from the Microsoft<br />

RAS-Client if a connection to other RAS servers exists.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!