[ Applies to ] StorageGuard / Dell Unity / Unified Storage
This article lists the recommended baseline checks for Dell Unity. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Dell Unity is a unified (SAN and NAS) midrange storage system managed through Unisphere.
Why hardening Dell Unity matters
Unity systems often host both block volumes and file shares. Hardening access, authentication, encryption, file-protocol and remote-support settings protects that data from unauthorized access and ransomware.
Recommended baseline checks
The baseline below contains 162 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-F9222T105V01 | Account lockout threshold |
| SG-M9380T105V01 | Anon user UID/GID |
| SG-F3568T105V01 | Anonymous user access |
| SG-C0451T105V01 | Antivirus scan status |
| SG-F8909T105V01 | Antivirus server configuration |
| SG-F1319T105V01 | Antivirus server redundancy |
| SG-F2103T105V01 | Approved AD domain |
| SG-M1651T105V01 | Approved admin group/user |
| SG-F9144T105V01 | Approved antivirus server |
| SG-M5118T105V01 | Approved Authentication server |
| SG-M3489T105V01 | Approved BMC/BIOS version |
| SG-C0449T105V01 | Approved DNS servers |
| SG-F7104T105V01 | Approved KMS server |
| SG-C0435T105V01 | Approved LDAP servers |
| SG-C0013T105V01 | Approved NTP servers |
| SG-M6832T105V01 | Approved Proxy server |
| SG-M3350T105V01 | Approved SNMP trap hosts |
| SG-C0015T105V01 | Approved Syslog servers |
| SG-C0331T105V01 | Audit log retention |
| SG-M1507T105V01 | Authentication server configuration |
| SG-M4360T105V01 | Authentication server is not secure |
| SG-M3640T105V01 | Authentication server redundancy |
| SG-M4152T105V01 | Central Certificate Authority (CA) status |
| SG-C0029T105V01 | Centralized log server |
| SG-C0233T105V01 | Centralized log server redundancy |
| SG-M4920T105V01 | Certificate issuer |
| SG-M5814T105V01 | Certificate public key algorithm |
| SG-M5046T105V01 | Certificate signature algorithm strength |
| SG-M1997T105V01 | Certificate Thumbprint Algorithm |
| SG-C0444T105V01 | Certificate type |
| SG-C0411T105V01 | CHAP authentication mode |
| SG-C0122T105V01 | CIFS SMB version enabled |
| SG-F1274T105V01 | CIFS/SMB share encryption enabled |
| SG-M6274T105V01 | Cloud connection |
| SG-C0396T105V01 | CloudIQ status |
| SG-M3007T105V01 | D@RE mode |
| SG-C0065T105V01 | Data at-rest encryption |
| SG-M7431T105V01 | Data copies status |
| SG-F2288T105V01 | Data in-transit encryption |
| SG-F7109T105V01 | Data retention mode |
| SG-M1541T105V01 | Default admin lockout |
| SG-M3802T105V01 | Default NFS access rights |
| SG-M6117T105V01 | Default password (service) |
| SG-M7356T105V01 | Default password (Unisphere) |
| SG-C0056T105V01 | Default passwords |
| SG-F9681T105V01 | DNS server configuration |
| SG-C0060T105V01 | DNS server redundancy |
| SG-M2111T105V01 | DNS service status |
| SG-M6765T105V01 | Email notification |
| SG-M1581T105V01 | Encryption status |
| SG-C0600T105V01 | End of support |
| SG-C0162T105V01 | Expired SSL certificate |
| SG-C0177T105V01 | FIPS mode status |
| SG-F5725T105V01 | FTP service status |
| SG-C0600T105V02 | Future end of support |
| SG-F4586T105V01 | HTTP service status |
| SG-M6204T105V01 | HTTP status |
| SG-F5474T105V01 | Idle session timeout |
| SG-C0206T105V01 | IPFilter status |
| SG-M7427T105V01 | IPMI default password |
| SG-M3329T105V01 | IPMI IP ACL |
| SG-M1569T105V01 | IPMI power control |
| SG-M7787T105V01 | IPMI security |
| SG-M7647T105V01 | IPMI Serial over LAN |
| SG-M6049T105V01 | IPMI status |
| SG-M4284T105V01 | IPMI user list |
| SG-M5454T105V01 | IPv6 status |
| SG-M6432T105V01 | iSCSI service status |
| SG-M8307T105V01 | Kerberos encryption strength |
| SG-M6829T105V01 | Keystore backup |
| SG-M3564T105V01 | KMIP status |
| SG-F4548T105V01 | KMS server configuration |
| SG-F2765T105V01 | KMS server redundancy |
| SG-M4119T105V01 | LDAP authentication strength (NAS server) |
| SG-C0039T105V01 | LDAP server configuration |
| SG-C0025T105V01 | LDAP server redundancy |
| SG-M8822T105V01 | LDAP SSL |
| SG-M1278T105V01 | Lockout duration |
| SG-M9601T105V01 | Lockout threshold |
| SG-C0427T105V01 | Login banner message |
| SG-C0426T105V01 | Login banner status |
| SG-M5689T105V01 | Maximum password age |
| SG-F8442T105V01 | Minimum account lockout duration |
| SG-M8845T105V01 | Minimum password length |
| SG-M7157T105V01 | NDMP service status |
| SG-M1796T105V01 | NFS authentication cache |
| SG-F9095T105V01 | NFS export ACL status |
| SG-M8967T105V01 | NFS secure mode (Kerberos) |
| SG-M1739T105V01 | NFS security |
| SG-F1270T105V01 | NFS security - Kerberos |
| SG-M5041T105V01 | NFS service status |
| SG-M9985T105V01 | NFS share IP ACL |
| SG-M7487T105V01 | NFS share rights |
| SG-M6555T105V01 | NFS versions enabled |
| SG-M6290T105V01 | NIS enabled |
| SG-F1049T105V01 | Non-default local admin |
| SG-C0231T105V01 | Non-default local users |
| SG-F7293T105V01 | NTP server configuration |
| SG-C0432T105V01 | NTP server redundancy |
| SG-C0172T105V01 | NTP service status |
| SG-M8129T105V01 | Packet reflection status |
| SG-F6416T105V01 | Password history |
| SG-M3239T105V01 | Password requirements |
| SG-M4379T105V01 | Password reuse policy |
| SG-M6545T105V01 | Proxy server secure (use socks) |
| SG-C0397T105V01 | Remote support configuration |
| SG-C0138T105V01 | Remote support status |
| SG-M1662T105V01 | Replication enabled |
| SG-F8320T105V01 | Replication link encryption |
| SG-M4240T105V01 | Required Authentication server |
| SG-C0450T105V01 | Required DNS servers |
| SG-C0439T105V01 | Required LDAP servers |
| SG-C0014T105V01 | Required NTP servers |
| SG-C0016T105V01 | Required Syslog servers |
| SG-M4571T105V01 | Restricted shell mode |
| SG-M9900T105V01 | Root user |
| SG-M7173T105V01 | Security administrator |
| SG-C0447T105V01 | Self-signed certificate |
| SG-M1804T105V01 | Session timeout |
| SG-M1935T105V01 | SMB ACL |
| SG-M1012T105V01 | SMB Encryption |
| SG-M5744T105V01 | SMB service status |
| SG-F8395T105V01 | SMB share access control list |
| SG-M7345T105V01 | SMB share rights |
| SG-M6650T105V01 | SMB signing |
| SG-M6505T105V01 | SMBv1 status |
| SG-M5760T105V01 | SMTP authentication |
| SG-M2935T105V01 | SMTP security |
| SG-F7270T105V01 | Snapshot auto-delete |
| SG-M1074T105V01 | SNMP authentication protocol |
| SG-C0058T105V01 | SNMP community default string |
| SG-M7663T105V01 | SNMP minimum storage alerts level |
| SG-M7600T105V01 | SNMP privacy protocol |
| SG-C0155T105V01 | SNMP service disabled |
| SG-M5396T105V01 | SNMP status |
| SG-M8538T105V01 | SNMP trap host configuration |
| SG-M9955T105V01 | SNMP versions enabled |
| SG-F3236T105V01 | SNMPv3 user configuration |
| SG-M5272T105V01 | SSH status |
| SG-M6594T105V01 | SSL key bitcount |
| SG-M2279T105V01 | SSO status |
| SG-M6197T105V01 | STIG mode |
| SG-M8615T105V01 | Support proxy transport type |
| SG-C0306T105V01 | Syslog communication protocol |
| SG-M4593T105V01 | Syslog minimum severity level |
| SG-M5365T105V01 | Syslog protocol |
| SG-C0019T105V01 | Target OS version - Unity OE |
| SG-M8110T105V01 | Target Unity Drive Firmware |
| SG-M5776T105V01 | Target Unity OE |
| SG-M1171T105V01 | Telnet service status |
| SG-C0390T105V04 | TLS level |
| SG-C0390T105V01 | TLS level - Unity |
| SG-M4502T105V01 | TLS security level |
| SG-C0448T105V01 | Trusted certificate-authority (CA) |
| SG-F9682T105V01 | Unapproved admin users |
| SG-F7664T105V01 | Unapproved user groups |
| SG-F8138T105V01 | Unused ports |
| SG-M3676T105V01 | Use of remote support policy manager |
| SG-C0213T105V01 | Use of secure LDAP |
| SG-F8768T105V01 | User role configuration |
| SG-M6644T105V01 | Valid non-expired certificates are used |
| SG-M8937T105V01 | Windows authentication protocol |
Related components
A complete baseline also covers the components that manage, connect to or protect Dell Unity. Review the configuration of:
- Unisphere CLI (UEMCLI) and REST API clients
- Dell PowerShell for Unity
- PowerPath
- CloudIQ and SupportAssist
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.