[ Applies to ] StorageGuard / Dell PowerMax / Block & SAN Storage
This article lists the recommended baseline checks for Dell PowerMax. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Dell PowerMax is Dell's flagship enterprise block storage platform, delivering NVMe performance, high availability and advanced replication for mission-critical workloads. It is managed through Unisphere for PowerMax and Solutions Enabler (SYMCLI/SYMAPI).
Why hardening Dell PowerMax matters
PowerMax arrays typically host an organization's most critical databases and applications. Securing the array, its management hosts and its replication links prevents unauthorized access and tampering, and protects the snapshot and replication copies you rely on for recovery.
Recommended baseline checks
The baseline below contains 218 checks, listed alphabetically.
| ID | Configuration check | Component |
|---|---|---|
| SG-C0207T121V01 | Absolute session timeout | PowerMax |
| SG-F3844T121V01 | Account lockout threshold | PowerMax |
| SG-F1005T121V01 | Anonymous user access (NAS) | PowerMax |
| SG-F7599T121V01 | Antivirus server configuration (NAS) | PowerMax |
| SG-F3738T121V01 | Antivirus server redundancy (NAS) | PowerMax |
| SG-C0163T121V02 | Approved AD domain | PowerMax |
| SG-C0163T121V01 | Approved AD domain (Solution Enabler) | PowerMax |
| SG-F2834T121V01 | Approved antivirus server (NAS) | PowerMax |
| SG-C0449T121V01 | Approved DNS servers (NAS) | PowerMax |
| SG-F1323T121V01 | Approved KMS server | PowerMax |
| SG-F9030T121V01 | Approved LDAP servers (NAS) | PowerMax |
| SG-C0013T121V01 | Approved NTP servers | PowerMax |
| SG-C0313T121V02 | Approved SE management servers | PowerMax |
| SG-C0313T121V01 | Approved SE management servers (Solution Enabler) | PowerMax |
| SG-C0348T091V01 | Approved SNMP trap hosts | Unisphere |
| SG-C0315T121V02 | Approved SYMAPI servers | PowerMax |
| SG-C0315T121V01 | Approved SYMAPI servers (Solution Enabler) | PowerMax |
| SG-M7304T121V01 | Approved SYMAPI/SYMCLI client hosts | PowerMax |
| SG-C0015T121V02 | Approved Syslog servers | PowerMax |
| SG-C0015T121V01 | Approved Syslog servers (Solution Enabler) | PowerMax |
| SG-F3167T121V01 | Audit log event types | PowerMax |
| SG-C0331T121V02 | Audit log retention | PowerMax |
| SG-C0331T121V01 | Audit log retention (Solution Enabler) | PowerMax |
| SG-C0001T091V01 | Audit logging status | Unisphere |
| SG-C0334T121V02 | Authorization control disabled | PowerMax |
| SG-C0334T121V01 | Authorization control disabled (Solution Enabler) | PowerMax |
| SG-M5839T121V01 | Authorization control enforcement mode | PowerMax |
| SG-C0335T121V01 | Authorization control enforcement mode (Solution Enabler) | PowerMax |
| SG-F4256T121V01 | Authorization policy status | PowerMax |
| SG-C0002T091V02 | Background audit logging (no-loss) | Unisphere |
| SG-C0002T121V01 | Background audit logging (no-loss) (Solution Enabler) | PowerMax |
| SG-C0032T121V02 | Central authentication | PowerMax |
| SG-C0032T121V01 | Central authentication (Solution Enabler) | PowerMax |
| SG-M4006T121V01 | Central Certificate Authority (CA) | PowerMax |
| SG-C0029T091V01 | Centralized log server | Unisphere |
| SG-C0029T121V01 | Centralized log server (Solution Enabler) | PowerMax |
| SG-M2285T121V01 | Centralized log server redundancy | PowerMax |
| SG-M4986T121V01 | Certificate issuer | PowerMax |
| SG-C0235T091V01 | Certificate key size | Unisphere |
| SG-F2935T121V01 | CHAP status - iSCSI initiator | PowerMax |
| SG-F5542T121V01 | CIFS SMB encryption policy (NAS) | PowerMax |
| SG-F7899T121V01 | Client Event daemon listening port | PowerMax |
| SG-C0396T091V01 | CloudIQ status | Unisphere |
| SG-C0318T121V02 | Cross-host authentication for client-server comm | PowerMax |
| SG-C0318T121V01 | Cross-host authentication for client-server comm (Solution Enabler) | PowerMax |
| SG-C0065T121V02 | Data at-rest encryption | PowerMax |
| SG-C0065T121V01 | Data at-rest encryption - SymCLI | PowerMax |
| SG-F5761T121V01 | Data in-transit encryption | PowerMax |
| SG-M6418T121V01 | Default password (Dell EMC SRM) | PowerMax |
| SG-M1057T121V01 | Default password (EMC Solutions Integration Service) | PowerMax |
| SG-M7938T121V01 | Default password (EMC ViPR, ViPR reporting) | PowerMax |
| SG-M7610T121V01 | Default password (EMC VSI for VMware vSphere Web Client) | PowerMax |
| SG-M7696T121V01 | Default password (ESRS Policy Manager Server) | PowerMax |
| SG-M3753T121V01 | Default password (Unisphere) | PowerMax |
| SG-M7550T121V01 | Default password (VASA/SE Virtual Appliance) | PowerMax |
| SG-C0056T091V01 | Default passwords | Unisphere |
| SG-C0056T121V01 | Default passwords (Solution Enabler) | PowerMax |
| SG-M3604T121V01 | Default SNMP strings | PowerMax |
| SG-M7035T121V01 | Dell EMC AppSync version | PowerMax |
| SG-M6747T121V01 | Dell EMC Unisphere 360 version | PowerMax |
| SG-M2122T121V01 | DNS configuration | PowerMax |
| SG-C0243T121V01 | DNS server configuration (NAS) | PowerMax |
| SG-C0060T121V01 | DNS server redundancy (NAS) | PowerMax |
| SG-F9544T121V01 | Domain user configuration | PowerMax |
| SG-M1196T121V01 | Email notification settings | PowerMax |
| SG-M3144T121V01 | Embedded Unisphere for PowerMax (eMGMT) | PowerMax |
| SG-M6360T121V01 | EMC ECOM certificate authentication status | PowerMax |
| SG-M3710T121V01 | EMC ECOM CIMRequest authentication | PowerMax |
| SG-M7791T121V01 | EMC ECOM CST authentication cache refresh interval | PowerMax |
| SG-M3536T121V01 | EMC ECOM CST logging status | PowerMax |
| SG-M2826T121V01 | EMC ECOM encryption algorithm | PowerMax |
| SG-M2487T121V01 | EMC ECOM external connection limit per host | PowerMax |
| SG-M8557T121V01 | EMC ECOM FIPS mode | PowerMax |
| SG-M8950T121V01 | EMC ECOM HTTP challenge mechanism | PowerMax |
| SG-M5783T121V01 | EMC ECOM Non-CIMRequest authentication status | PowerMax |
| SG-M6903T121V01 | EMC ECOM roles file encryption | PowerMax |
| SG-M6212T121V01 | EMC ECOM security logging enabled | PowerMax |
| SG-M2083T121V01 | EMC ECOM SSL cipher suite | PowerMax |
| SG-M2494T121V01 | EMC ECOM SSL client authentication | PowerMax |
| SG-M8371T121V01 | EMC ECOM SSL server authentication | PowerMax |
| SG-M8578T121V01 | EMC ECOM SSL/TLS protocol | PowerMax |
| SG-M3568T121V01 | EMC SRDF/Cluster Enabler Plug-in version | PowerMax |
| SG-M8662T121V01 | eNAS management interface | PowerMax |
| SG-M1174T121V01 | eNAS version | PowerMax |
| SG-C0600T121V01 | End of support | PowerMax |
| SG-C0600T085V01 | End of support | Solutions Enabler |
| SG-C0600T091V01 | End of support | Unisphere |
| SG-M1195T121V01 | Enginuity patch level | PowerMax |
| SG-M3628T121V01 | Enhanced (Kerberos) user authentication | PowerMax |
| SG-C0035T121V01 | Enhanced (Kerberos) user authentication (Solution Enabler) | PowerMax |
| SG-M7804T121V01 | ESRS Policy Manager 'Start Remote Terminal' setting | PowerMax |
| SG-C0175T121V02 | Event types enabled for audit logging (Unisphere) | PowerMax |
| SG-C0175T121V01 | Event types enabled for syslog (Solution Enabler) | PowerMax |
| SG-C0162T085V01 | Expired SSL certificate | Solutions Enabler |
| SG-M7965T121V01 | FCID Lockdown | PowerMax |
| SG-C0600T121V02 | Future end of support | PowerMax |
| SG-C0600T085V02 | Future end of support | Solutions Enabler |
| SG-C0600T091V02 | Future end of support | Unisphere |
| SG-M3885T121V01 | GNS DB backup | PowerMax |
| SG-C0205T121V02 | Host access list | PowerMax |
| SG-C0205T121V01 | Host access list (Solution Enabler) | PowerMax |
| SG-F8670T121V01 | HTTP port 80 disabled on management hosts | PowerMax |
| SG-M9122T121V01 | HTTP port disabled | PowerMax |
| SG-C0381T121V02 | HTTP service status | PowerMax |
| SG-C0381T085V01 | HTTP service status | Solutions Enabler |
| SG-C0209T121V01 | Idle session timeout | PowerMax |
| SG-M8937T121V01 | iSCSI - RADIUS configuration | PowerMax |
| SG-M6683T121V01 | iSCSI - Wire encryption (IPSec) | PowerMax |
| SG-M7289T121V01 | iSCSI CHAP authentication | PowerMax |
| SG-M2749T121V01 | Key server | PowerMax |
| SG-F4725T121V01 | KMS server redundancy | PowerMax |
| SG-C0039T091V02 | LDAP server configuration | Unisphere |
| SG-C0039T121V01 | LDAP server configuration (NAS) | PowerMax |
| SG-C0025T091V01 | LDAP server redundancy | Unisphere |
| SG-F3682T121V01 | LDAP service status (NAS) | PowerMax |
| SG-M1110T121V01 | Log event file permission | PowerMax |
| SG-F7401T121V01 | Login banner message | PowerMax |
| SG-F4742T121V01 | Login banner status | PowerMax |
| SG-M4965T121V01 | LUN masking | PowerMax |
| SG-M2075T121V01 | Mainframe Enablers version | PowerMax |
| SG-C0802T121V01 | Management API TLS enforcement | PowerMax |
| SG-M2046T121V01 | Maximum password age | PowerMax |
| SG-F3723T121V01 | Minimum password length | PowerMax |
| SG-F4842T121V01 | Multi-factor authentication | PowerMax |
| SG-F2596T121V01 | NFS exports minimum security (NAS) | PowerMax |
| SG-F1620T121V01 | Non-default local admin | PowerMax |
| SG-M9548T121V01 | Non-default local administrative user accounts | PowerMax |
| SG-C0231T121V01 | Non-default local users | PowerMax |
| SG-M5941T121V01 | NONSECURE/ANY connection | PowerMax |
| SG-C0171T121V01 | NTP server configuration | PowerMax |
| SG-C0432T121V01 | NTP server redundancy | PowerMax |
| SG-M9458T121V01 | PowerPath Encryption | PowerMax |
| SG-F4069T121V01 | RADIUS configuration | PowerMax |
| SG-M5695T121V01 | Remote replication | PowerMax |
| SG-M3438T121V01 | Remote support configuration | PowerMax |
| SG-C0138T091V01 | Remote support status | Unisphere |
| SG-F1841T121V01 | Replication link encryption | PowerMax |
| SG-C0450T121V01 | Required DNS servers | PowerMax |
| SG-C0014T121V01 | Required NTP servers | PowerMax |
| SG-C0349T091V01 | Required SNMP trap hosts | Unisphere |
| SG-C0320T121V02 | Required SYMAPI client hosts | PowerMax |
| SG-C0320T121V01 | Required SYMAPI client hosts (Solution Enabler) | PowerMax |
| SG-C0016T121V01 | Required Syslog servers (Solution Enabler) | PowerMax |
| SG-C0803T091V01 | REST API audit logging enabled | Unisphere |
| SG-C0804T091V01 | SCG certificate validation | Unisphere |
| SG-M1756T121V01 | SE Background Audit logging | PowerMax |
| SG-C0363T091V02 | SE client security level | Unisphere |
| SG-C0363T121V01 | SE client security level (Solution Enabler) | PowerMax |
| SG-M7918T121V01 | SE event / syslog configuration | PowerMax |
| SG-M6385T121V01 | SE Host access list | PowerMax |
| SG-M6445T121V01 | SE host NTP server configuration | PowerMax |
| SG-M9054T121V01 | SE host NTP server redundancy | PowerMax |
| SG-M6489T121V01 | SE Local audit log retention | PowerMax |
| SG-F3236T121V01 | Secure (HTTPS) VASA connection | PowerMax |
| SG-F4109T121V01 | Secure ECOM (SMI-S) communication | PowerMax |
| SG-M2449T121V01 | Secure management server communication | PowerMax |
| SG-C0368T121V01 | Secure management server communication (Solution Enabler) | PowerMax |
| SG-F3730T121V01 | Secure Remote Support (SSL) | PowerMax |
| SG-M1718T121V01 | Secure snaps | PowerMax |
| SG-F3795T121V01 | Secure VASA communication | PowerMax |
| SG-M6258T121V01 | Secure view of user authorization rules | PowerMax |
| SG-C0340T121V01 | Secure view of user authorization rules (Solution Enabler) | PowerMax |
| SG-M9135T121V01 | Security Administrator user | PowerMax |
| SG-C0447T085V01 | Self-signed certificate | Solutions Enabler |
| SG-F7644T121V01 | Separation of duties (storage admin vs security admin) | PowerMax |
| SG-F1073T121V01 | Server logging level | PowerMax |
| SG-C0330T121V01 | Shell access (Solution Enabler) | PowerMax |
| SG-M3965T121V01 | Snapshot retention | PowerMax |
| SG-M7590T121V01 | SNMP active clients | PowerMax |
| SG-C0058T121V01 | SNMP community default string (Solution Enabler) | PowerMax |
| SG-C0155T091V01 | SNMP service disabled | Unisphere |
| SG-C0156T091V01 | SNMP service enabled | Unisphere |
| SG-M1971T121V01 | SNMP trap client configuration | PowerMax |
| SG-C0347T121V01 | SNMP trap host configuration (Solution Enabler) | PowerMax |
| SG-C0347T121V03 | SNMP trap host configuration - Active Clients (Solution Enabler) | PowerMax |
| SG-C0123T091V01 | SNMP versions enabled | Unisphere |
| SG-M2565T121V01 | Solutions Enabler version | PowerMax |
| SG-M9544T121V01 | SRDF Adapter for VMware Site Recovery Manager version | PowerMax |
| SG-C0258T121V01 | SSH cipher strength | PowerMax |
| SG-M9595T121V01 | SSL certificate status | PowerMax |
| SG-M7895T121V01 | Storsrvd daemon restriction | PowerMax |
| SG-M8262T121V01 | Storsrvd directory access restriction | PowerMax |
| SG-C0323T121V02 | SYMAPI access ID | PowerMax |
| SG-C0323T121V01 | SYMAPI access ID (Solution Enabler) | PowerMax |
| SG-M3662T121V01 | SYMAPI encryption | PowerMax |
| SG-C0366T121V01 | SYMAPI encryption (Solution Enabler) | PowerMax |
| SG-C0181T121V02 | SYMAPI FIPS mode | PowerMax |
| SG-C0181T121V01 | SYMAPI FIPS mode (Solution Enabler) | PowerMax |
| SG-C0324T121V02 | SYMAPI host configuration status | PowerMax |
| SG-C0324T121V01 | SYMAPI nethost configuration (SYMAPI client) (Solution Enabler) | PowerMax |
| SG-M8168T121V01 | SYMAPI server session restrictions | PowerMax |
| SG-F2840T121V01 | SYMAPI service secure connection mode | PowerMax |
| SG-M5909T121V01 | SYMAPI SSL cipher suite strength | PowerMax |
| SG-M9631T121V01 | SYMAPI strict certificate client name validation | PowerMax |
| SG-C0225T085V01 | SYMCLI directory permissions | Solutions Enabler |
| SG-C0226T085V01 | SYMCLI file permissions | Solutions Enabler |
| SG-M7823T121V01 | Target array microcode version | PowerMax |
| SG-C0019T121V11 | Target OS version | PowerMax |
| SG-C0019T121V02 | Target OS version - Enginuity | PowerMax |
| SG-C0019T121V10 | Target OS version - Microcode | PowerMax |
| SG-C0019T085V01 | Target OS version - SE | Solutions Enabler |
| SG-C0019T085V03 | Target OS version - SYMAPI | Solutions Enabler |
| SG-M4769T121V01 | Target SYMAPI version | PowerMax |
| SG-C0385T085V01 | Telnet service status | Solutions Enabler |
| SG-C0249T121V01 | Tenant management network separation | PowerMax |
| SG-C0005T091V01 | TLS audit logging | Unisphere |
| SG-C0390T085V01 | TLS level | Solutions Enabler |
| SG-C0448T085V01 | Trusted certificate-authority (CA) | Solutions Enabler |
| SG-F1087T121V01 | Unapproved admin users | PowerMax |
| SG-C0119T121V01 | Unapproved user groups | PowerMax |
| SG-M7017T121V01 | Unauthorized user groups | PowerMax |
| SG-M6864T121V01 | Unisphere for PowerMax version | PowerMax |
| SG-M6509T121V01 | Unisphere Session timeout | PowerMax |
| SG-M2411T121V01 | Unisphere SMTP server configuration | PowerMax |
| SG-F7689T121V01 | Unused ports | PowerMax |
| SG-C0213T121V01 | Use of secure LDAP | PowerMax |
| SG-C0213T121V02 | Use of secure LDAP (NAS) | PowerMax |
| SG-F9615T121V01 | User role configuration | PowerMax |
Related components
A complete baseline also covers the components that manage, connect to or protect Dell PowerMax. Review the configuration of:
- AppSync
- Unisphere 360
- Solutions Enabler management hosts
- vApp management appliances
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.