Secure Remote Access
Security is the single major issue for remote network element
access. Many times remote access is provided by remote dial-up
modems, leaving any level of security to the network element being
connected to.
While leaving access security to the network element is not the
safest method of security, several vendors have developed
application software that resides on the field technicians portable
PC. This software is designed to "talk" to the equipment directly
through the PC's serial port, usually defaulted to Com Port 1.
The advantage to the vender application software is, unless it is
installed on the PC, you cannot access or provision the network
element. the disadvantage is it requires that the technician be on
site to provision or troubleshoot the equipment.
Serial Re-direct to an IP connection
Holly Street has developed software that resides on the technicians
PC to allow specific users and applications to be utilized through a
remote dial-up or IP connection, eliminating the need to be
physically on site.
Example, many SONET terminals are TL1 based and require
knowledge of that language to configure, provision and maintain the
equipment. Several vendors have developed application software
that converts TL1 to "English". The older versions of this software
will only connect to the SONET equipment through a PC serial port
(com ports 1-4), requiring the technician to be on site.
Another example is radio equipment used at cellular sites. As a
critical central core to the operation of a remote site, the radio is a
device that one does not want to have unauthorized access.
Several vendors have designed their radios such that an application
software package is required to provision and maintain the radio.
This software requires that only com port 1 or com port 1-4 be used.
This also requires that the technician be on site to perform these
duties.
HS Access Process Flowchart A
HS - 071403b
Drawing Title:
Ref Dwg Number:
This document contains proprietary information and shall
not be duplicated or disclosed without the written
permission of Holly Street Communications, Inc. By
accepting this document the recipient agrees to make every
effort to prevent unauthorized use of this information.
Page
of
1
1
Holly Street Remote Access Process
Holly Street has developed a secure process to ensure that remote
access to all network elements , legacy serial and the newer IP based
elements, is provided in a simple and secure manner.
Identifying and Approving the remote user
Holly Street has developed software that resides on the technicians
PC and communicates with the SA-8000 Serial Access Gateway family
to validate specific approved users and allows specific applications
to be utilized.
The HS-325 SetSecurity application will configure the users PC to
allow it to open the target application. Once the HS-325 has been
installed and run on the PC, when the remote site is access, the
remote site verifies that the PC has been registered and allows or
does not allow access to the network element.
Special Vender Application Software
When the network element to be accessed requires a vender specific
application software package, the SA-8000 series allows the software
to be activated remotely. The HS-375 will provide a ComPath function
that points the serial port to an assigned IP address. All data targeted
to the serial port is also pointed towards the remote IP port, allowing
the application software to communicate to the remote network
element as if one was physically in front of and connected to the
device.
Holly Street Communications, Inc.
5571 San Jose Drive
Pleasanton, California 94566
www.hollystreetcomm.net