Securing Avaya one-X Portal for IP Office

Last Updated : Aug 30, 2023 |

Procedure

  1. Log in to the default Avaya one-X® Portal for IP Office Administrator account and change the password to a strong password of 8 or more characters.
    • This account is used by Avaya one-X® Portal for IP Office if IP Office referred authentication service is not available, see User Accounts and Rights of Access for more information.

  2. For subsequent password management, go to the Avaya one-X® Portal for IP Office Configuration > User page. Any unused administrator accounts must be deleted.
  3. On the Avaya one-X® Portal for IP Office administration page, navigate to Configuration > Providers > CSTA-Provider > Edit and configure the password used to access IP Office. The password must match the password configured for the IP Office Manager user EnhTcpaService.
  4. If Avaya one-X® Portal for IP Office clients are to be used externally, follow Hardening for Remote Worker Operation.
  5. If external Avaya one-X® Portal for IP Office clients are configured to support VoIP calls, follow Limiting IP Network Exposure.
  6. Avaya one-X® Portal for IP Office offers both an HTTP (8080 + 8069) and HTTPS (8443/9443 + 8063) interface for web clients. HTTPS must be used for external access. The HTTP ports can be disabled using the setting Security > Protocol > Secure Connection (HTTPS).
  7. To administer an Identity Certificate for the HTTPS interfaces on a Linux-based server, see Update Certificates.
  8. Log in to the default Superuser backup and restore account and change the password to a strong password of 8 or more characters. For subsequent password management, go to the Avaya one-X® Portal for IP Office AFA page Configuration > Edit page.
  9. If the host server operating system is Microsoft Windows, consult the relevant Microsoft OS security guidelines at https://technet.microsoft.com/en-us/library/windows-server-security.aspx. For more general information, see https://technet.microsoft.com/en-us/security/default.aspx
  10. The Openfire console should not normally be enabled. If in exceptional circumstances, it is enabled under the direction of Avaya, then it must be disabled as soon as possible afterwards. The command to disable is at: http://ipofficekb.avaya.com/businesspartner/ipoffice/mergedProjects/oneXportaladmin/diabling_openfire_admin_consol.htm
  11. If the application is not used, it should be disabled using the Platform View > System > Services > Automatically Start setting.