Security 13-1CCCChhhhaaaapppptttteeeerrrr 11113333SSSSeeeeccccuuuurrrriiiittttyyyyThe Netopia 4752 provides a number of security features to help protect its configuration screens and yourlocal network from unauthorized access. Although these features are optional, it is strongly recommended thatyou use them.This section covers the following topics: “Suggested Security Measures” on page 13-1 “User Accounts” on page 13-1 “Telnet Access” on page 13-3 “About Filters and Filter Sets” on page 13-4 “Working with IP Filters and Filter Sets” on page 13-11 “Firewall Tutorial” on page 13-19 “RADIUS Client Support” on page 13-30Suggested Security MeasuresIn addition to setting up user accounts, Telnet access, and filters (all of which are covered later in this chapter),there are other actions you can take to make the Netopia 4752 and your network more secure: Change the SNMP community strings (or passwords). The default community strings are universal andcould easily be known to a potential intruder. Set the answer profile so it must match incoming calls to a connection profile. Leave the Enable Dial-in Console Access option set to No. When using AURP, accept connections only from configured partners. Configure the Netopia 4752 through the serial console port to ensure that your communications cannot beintercepted.User AccountsWhen you first set up and configure the Netopia 4752, no passwords are required to access the configurationscreens. Anyone could tamper with the router’s configuration by simply connecting it to a console.However, by adding user accounts, you can protect the most sensitive screens from unauthorized access. Useraccounts are composed of name/password combinations that can be given to authorized users.