Security management
4.2.5 Security management
- Security management The function is the key infrastructure security function that monitors the overall security status of the system and controls the policy from the center.(Identification, auditing, self-protection, access, and session management)It's a way to control security settings that are classified by system.
4.2.5.1 Identification and identification
4.2.5.1.1 Password policy
It's a key security setting that enforces password creation rules for every user account in the system, preventing account hijacking and random entry attacks from vulnerable passwords.
- Password path: It specifies the minimum and maximum length of the password to ensure basic security robustness.
- Letters combined(It's complicated.): You can choose the essential elements that must be included in the password from the English capital, the English capital, the numbers, the special characters, individually, and you can force the complexity.
- Restrictions on the use of vulnerable patterns: It strictly blocks vulnerable and easy-to-trace patterns, like the repetition of the same characters or the sequence of characters, from being included in the password.
4.2.5.1.2 Policy of failure of certification
It's an automatic blocking feature to protect your system and user account from malicious logging attempts.
- Maximum number of failures: It sets the permissible parameters for consecutive log-in failures. If the user exceeds this number and misplays the password, the account is immediately locked for system protection.
- Lockdown time.(I'm not going to.): It sets the time to temporarily block system access to the locked account beyond the number of failures, in minutes. After the set time, the account locks automatically unlock.
4.2.5.2 Audit management
This feature is that when the space is full to store the audit logs of the system, the administrator can save the policy in advance about how the system will respond, depending on the nature of the service being operated and the security regulations.
- Cover-up: When the storage space is full, you delete it from the oldest audit log in a sequential order and then you cover it with a new log.
- Interruption: If there is no storage space, it determines that the log cannot be left in the system and immediately stops operating, then waits for the administrator to intervene.
4.2.5.3 Self-defense
4.2.5.3.1 Performing self-testing of security functions
It's a security feature of the system that checks in real time that the main processes are running normally.
- Subject to inspection
- The encryption module: It's to make sure that the user's password or important data is encrypted normally.
- Database: This is the data base. Check the connection status to the DB server and the data reading/writing functionality.
- Proxmox API: Virtualized infrastructure(Proxmox) To control the API I'm going to check that the communication is going well.
- How to use: And then you select the checkbox for the item to check, [[Self-diagnosis started] And if you click on that button, the test is done immediately.
4.2.5.3.2 Response policy for failure of self-test
Failure to perform self-testing on a regular basis, or manually, within the system.(Error) It sets the system's mode of operation when the flare occurs.
- A warning warning.
- The action: Even if the test of the module fails, The entire system is running the same.Instead, you'll immediately notify the manager of the problem.(Log records, screen views, and so on.) I warn you.
- System shutdown - The urge of the state of Xi'an - The action: One of the modules set by this policy is If any of the tests fail, we'll immediately block access and operation of the entire system to prevent a secondary security incident or data contamination.So we're going to do that. VirtOn The System Backup & Restore feature is a virtual machine currently running(VM) It's a snapshot of the whole thing and it's stored in the operating system.(OS) The database.(DB) It includes all the systems states, including application settings, log files, and so on, so it's possible to recover from a ransomware infection or server failure.
4.2.5.3.3 Disconnect the system
If the entire access is blocked by the system blocking policy, the pre-issued The recovery secret.(Recovery Secret) You can just undo the scale.
1) Recovery secret is issued.
Setup > Security management > Self-protectedOn the screen. [[Recovery secret is issued] Click on the button.- The recovery secret that was issued was: Just one shot on the screen.So we're going to check it out immediately and secure the storage.(And the internal intelligence system.) I'm going to keep it.
- I'm going to get the recovery secret. If you re-issued the old secret, you can immediately discard it.It's not available.
2) System shutdown off
- If the system is blocked,
System shutdown offIt moves to the screen. - Enter the recovery secret that was issued and stored. [[Block off] Run the program.
- Normal disconnection logins and main function access are restored.
- After the dismantling, the cause of failure.(Failed self-test items) We'll have to check it out and then restart operations.
4.2.5.4 Before we start (Authorization and access)
- Access to the site: This page covers the core functions of the system, so the administrator(ADMIN) And the chief executive officer.(SUPER_ADMIN) Only authorized users can access it.
- Backup object selection:
- VirtOn To use the entire system backup and recovery, we have a current VirtOn This is a distributed QEMU VM You have to register the nodes and VMIDs first.
4.2.5.4.1 Activation/inactivation of the backup function
You can control the backup function with the toggle switch on the top right of the page.
- Activate the (ON): You do a system scan and you call in the backup form and the list.
- Deactivation (OFF): It's disabled, and the automatic backup schedule won't work.
4.2.5.4.2 Set the policy for backup (Configuration)
You can set the backup storage location, period, and storage period in the middle of the settings panel. [[Please save] You just press the button.
Select the backup storage (Storage)
You select the disk where the backup file is physically stored.
- When you open the drop-down, you see a list of connected storage and the remaining storage capacity.
- We recommend that you choose a storage that is large enough.
Set the automatic backup schedule (Schedule)
The system automatically specifies the time to perform the backup.
- Not in use: Automatically back up. (Only manual backup is possible.).
- Every day, every week, every month: It's a busy morning.(00:00, 02:00, 04:00, and so on.) You can choose.
Set the backup retention time (Retention)
It prevents old backup files from taking up disk space.
- Entered the number(Basic 30 days.) The last backup file is automatically deleted at 3 a.m. every day.
4.2.5.4.3 to run the backup
▶ Manual backup (Manual Backup)
It creates a backup immediately before an emergency check or before any significant changes are applied.
- The top. [▷ Now click on the Create a new backup button.
- When the backup starts, the progress rate is the same up there.(Blue Bar) It's going to be shown.
- The backup is Proxmox So it's in the background, so even if you move the page, it's still going on.
Monitoring and interrupting progress
- When backup or recovery is going on, real-time progress rate(%) It's shown in this gauge.
- If you want to stop working, the guy on the right is [You can force it to close by clicking the X stop] button.
4.2.5.4.4 Management and monitoring of the backup list
You can check and manage all the backup files stored in the table below.
Filtering (Storage inspection.)
Drop down from the top right of the table.(Select Box) You can only collect backups that are stored in specific storage.
- All the storage: I'm going to show you the entire backup list as up to date.
- Individual storage (Yes, the NAS.): We filter only the files in the storage, and then we show the number of files in each storage together.
Table information
- The storage room. (Storage): The name of the storage where the file is located. (The shape of the badge)
- File name: Proxmox Back up file name. (
vzdump-qemu-105...) - Temporary creation: Date and time of completion of the backup
- The capacity: The size of the backup file (GB unit)
Delete the backup
- The unnecessary backup file is on the right side of the screen. [Delete the button(Icon of the red towel.) You can delete it by pressing it.
- When you delete, the check window opens, and if you approve, the file is permanently deleted.
4.2.5.4.5 System recovery (Restoration)
When a problem occurs, it restores the system to a backup file at a specific point in time.
️ Warning: How to recover (Safe Clone Restore) VirtOn"New virtual machines" to prevent the server from stopping(New VM)" and then it restores the existing server.(105th.) It's safe because it's not covered.
The recovery procedure.
- Right of the file at the desired point in the backup list [Repair button(Blue icon) Click on this.
- Check the message box and read the contents. [I'll just click on [check].
- The upper gauge shows the recovery progress rate. (Yes: "We're safely restoring the system with a new virtual machine"...).
- When the recovery is 100% complete:
- Proxmox New number on(Yes, I know. VM 106) And then a virtual machine is created with a virtual machine.
- The manager is Proxmox The console is the same. VM(Yeah, 105 is the number.) Turn off the power, baby. VM(Yeah, 106 is the number.) Turn on and switch services(Switching) It does.
4.2.5.4.6 Problem solving (Troubleshooting)
- The backup button is disabled: If you're already running a backup or recovery, you'll press the button to stop the backup from running, wait until the task is done, or wait until the rest is done. [Please press the [Stop] button.
- The gauge is at zero: In the case of bulk storage, the initial allocation of space can take time, and if you wait about a minute or two, the numbers normally go up.
- I can't get in after recovery: The restored system is a new one. VM It's a way to prevent IP collisions. VM Turn off the bird VM Check if you booted it.
4.2.5.5 Administrator IP access control (IP Access Control)
VirtOn To prevent external attacks and unwanted access IP-based access control(The white list.) It's a good idea.
4.2.5.5.1 Security policy (The working principle.)
The system automatically switches to mode depending on the status of the whitelist registration.
Opening mode (Open Mode)
- ConditionsIf the whitelist IP is zero,
- The movement.All IP access not on the blacklist is allowed.
Lock mode (Lockdown Mode)
- ConditionsIf you have more than one IP on the whitelist,
- The movement.: Access to only the whitelist IP (Strong security)
4.2.5.5.2 Use of the main functions
4.2.5.5.2.1 My IP address is registered (Recommended)
When you first set up the whitelist, it's a feature to prevent IP ranking itself.
- Upper warning banner. The IP addresses you're currently connecting to are not on the whitelist! I'm sure.
- [[Typing my IP] Click the button.
- After automatically checking the IP entered [[added] Click on it.
4.2.5.5.2.2 Directly register the IP
- Type selected
WHITELISTAllowed IP: (Administrator PC, office IP)BLACKLISTBlocked IP: (Suspicious IP addresses, etc.)
- IP address
- Only one IP allowed.
- Yes, I know.
123.456.0.10 - You know, Wildcard, CIDR.(
192.168.0.0/24) It's impossible.
- Notes
- Identifiable description input
- Yes, I know.
OOO team home
4.2.5.5.2.3 IP correction and deletion
- IP correction : Double click list or pencil icon click is available, modification method is the same as IP direct registration
- Delete the IP : List of junk boxes can be deleted when clicking on icon
4.2.5.5.2.4 Automatically shut down (IPS)
- I failed to log in repeatedly in a short time.
- Find the IP address in the list of cities. [[deleted] Remove immediately when you click the button.
4.2.5.5.3 Emergency action guides (Lockout situation)
Delete the only whitelist IP or If you need an emergency access from an unregistered location, you can block access.
In this case, Contact the DB administrator directly and take actionWe need to.
4.2.5.6 Session management
This function controls the logged-in user's log-in time, inactive session management, and the number of simultaneous log-in devices, preventing security accidents caused by unauthorized access or account sharing.
- Session timeout: It calculates from the time the user logs in, and if the set time expires, it unconditionally ends the session and sets the maximum access time limit for enforced log-out.
- Time of the deadline: It calculates from the time the user is active, and when the set time expires, it expires the session and sets the time limit for the forced log-out.
- The items that acknowledge the activity are clicks, key entries, pointers, route moves, save requests, protected API Calling (Except for the single, polling and automatic)
- You can specify exception roles and permissions to reduce discomfort about the termination of inactive sessions, and you can exclude the roles that you have selected and any of the selected permissions.
- Simultaneous access session limits: It limits the maximum number of people you can log in from multiple devices or browsers at the same time as a single administrator account.
- The session-related settings are new session-based, so if you want to apply them right away, Log out and log back in. Do it.