2.8 Protocol Access Controls - 'telnet.access has been configured'

Information

Data ONTAP allows the configuration of filters for the following protocols: RSH, telnet, SSH, HTTP, SNMP, NDMP, SnapMirror, and SnapVault. The filters can specify host names, IP addresses, IP subnets, or interface names, which are either allowed or disallowed for each protocol. Each application then uses the filter on the listening socket to control access. In conjunction with disabling insecure protocols, this allows fine-grained control of access from limited areas. NetApp recommends as a best practice that you configure protocol access filters for any administrative protocol that is enabled on the NetApp storage system.

Solution

Configure telnet to allow connections only from known trusted hosts

See Also

http://media.netapp.com/documents/tr-3649.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4

Plugin: NetApp

Control ID: 47f66f5b74ba2cfde4b3f79d3d58e722bc2905aa38dacd3c8ac6f9026cba24ed