Hardening tips for interface modules - Synergis Softwire 11.5.3

Synergis™ Softwire Integration Guide 11.5.3

Product
Synergis Softwire
Content type
Guides > Integration guides
Version
11.5
Release
11.5.3
ft:locale
en-US
Last updated
2025-01-23

If system security is a priority for your organization, we recommend that you follow the hardening advice for interface modules.

This section lists general hardening tips for all interface modules. Manufacturer-specific hardening tips are tagged with Hardening in each manufacturer's respective integration topics. For hardening guidelines for the entire system, see the Security Center Hardening Guide.

Use the latest interface module firmware

Access control hardware manufacturers frequently update their products and fix security vulnerabilities with new firmware. We continuously test the compatibility of the new firmware published by third-party manufacturers with Synergis™ Softwire. In this guide, the latest firmware that is certified compatible with Synergis Softwire is listed as recommended firmware.

We recommend upgrading interface module firmware using the Hardware inventory task in Config Tool rather than the Synergis™ Appliance Portal because you can do the following in the Hardware inventory task:
  • Upgrade interface modules in batches or individually.
  • Schedule upgrades and configure email notifications for failed upgrades.
  • View the upgrade progress and current firmware for each interface module.
  • Upgrade Mercury SIO modules and interfaces.
For more information about upgrading firmware in the Hardware inventory task, see Upgrading access control unit firmware and platform, and interface module firmware.

For more information about upgrading firmware in the Synergis Appliance Portal, see Upgrading interface module firmware through the Synergis Appliance Portal.

NOTE: Certification tracking of Synergis-partner firmware is now done within the scope of Synergis Softwire 11.5.3. If a newly discovered vulnerability is fixed in a more recent firmware than the one we certified, then apply it using the manufacturer's software.

Never use default passwords

Many access control devices are shipped with their default administrative passwords. These passwords aren’t private or secure. Change these passwords on each device's web page before enrolling them on your Synergis™ unit. The most secure way to change passwords is to configure a separate network, ideally over HTTPS.

Delete unused interface modules from your hardware configuration

Delete any unused interface modules from your Synergis appliance's hardware configuration. Certain interface modules can leave open ports that make your appliance vulnerable to attacks. You can delete the unused interface modules either from the Synergis Appliance Portal or from Config Tool. For more information, see the topics corresponding to each interface module manufacturer.

Enable DESFire EV2 secure communication

If you have STid SSCP or OSDP transparent readers in your system, enable the DESFire EV2 secure communication on all your workstations and Synergis units. For more information, see Enabling DESFire EV2 secure messaging.