Appliance Administration: Restrict Accounts, Networks, and Ports, Enable a STUN Server, Set Up Syslog, Enable Login Agreement, Reset Admin Account

Security :: Appliance Administration

Security :: Appliance Restrictions

Manage access to /appliance administrative interface accounts by setting how many failed logins are allowed. Set how long an account is locked out after passing the failed login limit. Also, set the number of days a password may be used before expiration, and restrict the reuse of previous passwords.

You can restrict access to your appliance’s administrative interface by setting network addresses that are or are not allowed, and you can select the ports through which this interface is be accessible.

In the Accepted Addresses field, define IP addresses or networks that are always granted access to /appliance. In Rejected Addresses, define IP addresses or networks that are always denied access to /appliance. Use the Default Action dropdown to determine whether to accept or to reject IP addresses and networks not listed in either of the above fields. In the case of overlap, the most specific match takes precedence.

If, for example, you want to allow access to 10.10.0.0/16 but reject access to 10.10.16.0/24 and reject access from anywhere else, you would enter 10.10.0.0/16 in the Accepted Addresses field, enter 10.10.16.0/24 in the Rejected Addresses field, and set the Default Action to Reject.

 

Security :: Appliance Administration :: Stun Service

The Bomgar Appliance can be configured to run a STUN service on UDP port 3478 to help facilitate peer-to-peer connections between Bomgar clients. Check the Enable local STUN Service box to use this functionality.

 

Syslog

You can configure your appliance to send log messages to up to ten syslog servers, separating entries by commas. Select the data format for the event notification messages. Choose from the standards specification RFC 5424, one of the legacy BSD formats, or Syslog over TLS. Bomgar Appliance logs are sent using the local0 facility.

Note: Syslog over TLS always uses TCP port 6514

For a detailed syslog message reference, see the at www.bomgar.com/docs/privileged-access/how-to/integrations/syslog/.

 

Prerequisite Login Agreement

You can enable a login agreement that users must accept before accessing the /appliance administrative interface. The configurable agreement allows you to specify restrictions and internal policy rules before users are allowed to log in.

 

Reset Admin Account

You can choose to select Reset Admin Account, which restores a site’s administrative username and password to the default should the login be forgotten or need to be replaced.