Creating a High Security Site

You can create a Site with features that will help you comply with PCI DSS requirements--or if you just want a higher level of security with a Site that can monitor, report, and/or warn you when any of the high security settings are changed to a less secure mode. When you run the Server and Site creation wizards, you have the option to create a Site with or without high security features. If you choose to create a high security Site, the Site Setup wizard also determines the status of the Auditing and Reporting Module (ARM); if high security is enabled, but ARM is not, a warning message appears to inform you that you must enable ARM on EFT Server before creating the Site.

For details of configuring Servers and Sites, and enabling ARM on EFT Server, refer to the following topics:

You will need the following information to create and configure a high security Site:

  • IP address and port for Auditing and Reporting database (ARM (Auditing and Reporting Module; captures the transactions passing through EFT Server and provides an interface in the Administrator where you can use preconfigured or your own custom reports to query, filter, and view transaction data.) must be enabled for HS-enabled Sites)

  • If the SMTP server requires authentication, you will need to know the administrator e-mail address and SMTP server name, port, and login information (for e-mailing the compliance Report).

  • If you use default values for administrator port (1100), DMZ Gateway port (44500), FTP banner message, or SFTP banner message, a warning appears in which you must change the value or provide a reason for using the default. The reason that you provide will appear in the Description field of the compliance report.

    The wizard performs several checks and asks you to provide information based on the results of those checks, including:

    The wizard is quite intuitive and provides instructions where necessary. The wizard pages change based on your selections. The procedure below walks you through the most common scenarios.

    Because EFT Server does not manage NT/LDAP accounts, when you create a High Security Site that uses LDAP or Windows Active Directory authentication, the following features are not available and not audited for the compliance Report:

     

    To configure a high security Site

    1. Do one of the following:

    2. The Site Setup wizard Welcome page appears.

    3. Click Strict security settings, then click Next. The Site name page appears.

    4. In the Site name box, type a name a unique name for the Site. The default name is MySite, but you change it to anything you want. The name you provide here will appear in EFT Server tree in the left pane of the Administrator and in reports and messages.

    5. In the Listening IP box, specify the IP address the Site should listen on, or leave the default of All Incoming.

    6. Click Next. The Site Root Folder page appears.

    7. In the Site root box, leave the default or click Browse to specify the root folder.

    8. In the Additional options area, select the check boxes as needed:

    9. Click Next. The User Authentication page appears.

    10. In the Authentication type list, specify one of the following authentication methods that this Site will use to authenticate user connections:

    11. Click Next. The Server Authentication settings page appears.

    12. The default path to store the user database appears in the box. If you want to store the user database in a different location, click the Browse icon or type the path in the box.

    13. Click Next. The Perimeter Network Security page appears.

    14. Specify whether to connect the Site to EFT Server's DMZ Gateway.

    15. Click Next. If you specified a default port for DMZ Gateway, the Vendor Defaults page appears.

    16. Change the port number to a non-default number, or provide a reason for keeping the default port. (The reason will appear in the Description box of the compliance report.)

    17. Click Next. If EFT Server was configured with the default Administrator port of 1100, the Vendor Defaults page appears for you to change the Administrator port or provide justification for using the default.

    18. Click Next. The Data Retention and Disposal page appears.

    19. Do one of the following:

    20. Click Next. The Administrator Account Password Security page appears.

    21. Keep the default of enabling the administrator account password security settings or click Continue without changing administrator account password security settings, then provide the justification and compensating control. (The reason will appear in the Description box of the compliance report.)

    22. Click Next. The Daily PCI DSS Audit Report page appears.

    23. Do one of the following:

    24. Click Next. The Data Sanitization page appears.

    25. Do one of the following:

    26. Click Next. The Connection Protocols page appears.

    27. Select one or more check boxes for the protocol(s) and specify the port numbers that this Site will use to connect to EFT Server.

    28. If you specify plain-text FTP or HTTP, after you click Next, EFT Server will prompt you to disable these unsecure protocols or continue and supply justification.

    29. Click Next. The Vendor Default page appears if the default SFTP banner message is used on EFT Server.

    30. Do one of the following:

    31. Click Next. The Site Setup Completed page appears.

    32. You are offered the option of continuing to the User Creation wizard or quitting the wizard. Click an option, then click Finish. If you chose Run New User Creation wizard, the User Creation wizard Welcome page appears.

    The HS-enabled Site appears in the tree on the Server tab.