Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

EcoStruxure IT Gateway security considerations

EcoStruxure IT Gateway security

The EcoStruxure IT platform is security hardened with a mandatory two-factor authentication and high encryption standards.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • EcoStruxure IT Help Center
  • EcoStruxure IT Help Center Categories
  • EcoStruxure IT Security
  • EcoStruxure IT Gateway security
  • EcoStruxure IT Gateway security considerations
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • EcoStruxure IT forum

  • APC UPS Data Center & Enterprise Solutions Forum

Previous Next

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite

EcoStruxure IT Support

Submit a support request for additional assistance with EcoStruxure IT software.

Request Support
Back to EcoStruxure IT Gateway security
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
1 Like
3793 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

EcoStruxure IT Gateway security considerations

Picard EcoStruxureIT
‎2020-10-30 07:14 AM

Last Updated: Sisko JLehr Sisko ‎2024-09-04 04:42 AM

Security hardening

 

  • The EcoStruxure IT Gateway is intended to be accessed from within a secure network, and not over the internet.  Therefore, do not make the web UI accessible via the internet.

  • Regularly apply available operating system patches and security updates to the Gateway server.

  • Follow the recommended hardening guidelines for the operating system. Refer to Gateway default ports when configuring the firewall.

  • Do not allow local operating system login access to the Gateway server, except for IT administrators.  

  • Use SNMPv3 instead of SNMPv1 and enable encryption and authentication whenever possible.  Use HTTPS instead of HTTP for NetBotz devices. Use SCP instead of FTP for firmware updates and device configuration. Even when these devices are on a private network, using a secure protocol as part of a defense-in-depth strategy is recommended.

  • By default, none of the protocols for communicating with the end devices are active. They are enabled by adding new device credentials.  The only external ports enabled are

    • 443 for the web application, both inbound for the Gateway web UI, and outbound to communicate with the EcoStruxure IT web application.  This can be changed at install to use another port if desired.

    • 1062 for SNMP traps.

 

Password policy

 

There is no default password for the EcoStruxure IT Gateway.  Upon first launching system, the user is required to set the admin password.

 

The EcoStruxure IT Gateway password policy now requires:

 

  • At least 10 characters in length
  • At least 3 of the following 4 types of characters:
    • Lower case letters (a-z)
    • Upper case letters (A-Z)
    • Numbers (0-9)
    • Special characters (Example: !@#$%^&*)
  • No more than 2 identical characters in a row (Example: aaa is not allowed)

 

Strong passwords are enforced when you first create your password and when you change your password. You are not required to change your existing password after updating your Gateway.

 

Permissions

 

Application

 

  • There is only one permission level on the Gateway. The Gateway UI is intended for application administrators only. This user has the ability to:
    • Create, delete, and change passwords for users, but cannot change usernames
    • Configure device discoveries
    • View sensor and alarm information from discovered devices
  • Starting in Gateway version 1.9, strict password enforcement is in place. It is recommended to update your password after upgrading and to update your password periodically since passwords do not automatically expire.

 

IT administration

 

  • A local administrator account on the operating system of the Gateway server is required in order to install the software, perform the other security hardening activities, and to retrieve log files if necessary.

  • The Linux installer creates a local service account under which the applications runs. This service also performs database backups.  On Windows, the service runs as the Local System account.

  • Software updates can be done three ways:

    • Auto update - When this option is selected in the EcoStruxure IT web application, software updates are automatically pushed to the Gateway.  No additional user accounts or interaction is required.

    • Cloud initiated - Software updates are initiated by a user logged into the EcoStruxure IT application.  No additional user accounts or interaction is required.

    • Local, manual - A local operating system administrator may also download the software update to the Gateway server and manually run the installer.  

 

Decommissioning

 

  • To decommission a Gateway server, it is recommended that you re-image the machine. This will erase all data and set all operating system settings back to their defaults.

  • If re-imaging is not possible, first run the uninstaller, then make sure the data is removed from the install location using a secure erase utility. This will remove the application, data, and certificate.

  • Log in to the organization's EcoStruxure IT account and remove the association with the Gateway from the account.

Was this article helpful? Yes No
No ratings

Link copied. Please paste this link to share this article on your social media post.

Didn't find what you are looking for? Ask our Experts
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of