Decision acceptance deadline

11.08.26 (inclusive)

Form of award

By agreement

Product status

Idea

Task type

ICT tasks

Сфера применения

Robotics

Область задачи

Technologies in telecommunications

Type of product

Software/ IS

Problem description

Remote server hardware management interfaces provide full administrative access to physical servers and are critical infrastructure elements. Currently, it is necessary to exclude the possibility of their detection and use from the Internet, providing access exclusively for authorized administrators.

Expected effect

The server hardware management interfaces are completely removed from public access, connection is carried out only through a secure channel by authorized administrators, and the risk of unauthorized access is significantly reduced.

Full name of responsible person

Musabekov Shyngyz

Purpose and description of task (project)

Goal Provide the highest possible level of protection for remote management interfaces of server equipment by completely isolating them from the Internet. Functional requirements Access restrictions It is necessary to implement a mechanism that ensures: • lack of direct access to iDRAC from the Internet; • access exclusively for trusted administrators; • using secure connection methods; • eliminating the possibility of detecting interfaces during external scanning. Protecting administrative access It is necessary to provide for the possibility of: • VPN access; • using a list of trusted IP addresses; • Multi-factor authentication applications (if supported); • logging of all connections; • monitoring of unsuccessful login attempts. Additional security measures The solution should provide for the possibility of using: • Network segmentation; • Jump Server (Bastion Host); • ACL; • VPN; • Firewall; • IDS/IPS; • Security event monitoring systems; • other specialized protective equipment. Security check After implementation, you must confirm: • no access to iDRAC from an external network; • the ability to connect only through an approved access scheme; • No false positives for administrators; • correct registration of all user actions.

Note