[ Applies to ] StorageGuard / Dell PowerScale / NAS Solutions
This article lists the recommended baseline checks for Dell PowerScale OneFS. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Dell PowerScale (formerly Isilon) is an enterprise scale-out NAS platform, running OneFS, for high-volume storage, backup and archiving of unstructured data.
For AI-focused deployments, see also Dell PowerScale All-flash.
Why hardening Dell PowerScale matters
PowerScale clusters store large shared file repositories that are attractive targets for data theft and ransomware. Hardening access zones, protocols, authentication, auditing and SmartLock settings protects file data and supports recovery.
Recommended baseline checks
The baseline below contains 212 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-M1057T073V01 | /ifs root share status |
| SG-F7781T073V01 | Absolute session timeout (HTTP) |
| SG-M2008T073V01 | Access Based Enumeration |
| SG-C0393T073V01 | Account lockout threshold |
| SG-F6768T073V01 | Account lockout window |
| SG-C0452T073V01 | Antivirus server configuration |
| SG-C0453T073V01 | Antivirus server redundancy |
| SG-C0433T073V01 | Approved Active-Directory provider |
| SG-C0163T073V01 | Approved AD domain |
| SG-M4529T073V01 | Approved admin user / group |
| SG-C0053T073V01 | Approved antivirus server |
| SG-M2965T073V01 | Approved authentication provider |
| SG-C0449T073V01 | Approved DNS servers |
| SG-M2687T073V01 | Approved external syslog servers |
| SG-C0437T073V01 | Approved identity provider servers - Kerberos |
| SG-M5651T073V01 | Approved Isilon release |
| SG-M7454T073V01 | Approved Kerberos providers |
| SG-C0434T073V01 | Approved Kerberos realm |
| SG-M9293T073V01 | Approved KMIP servers |
| SG-F2445T073V01 | Approved KMS server |
| SG-C0435T073V01 | Approved LDAP servers |
| SG-C0013T073V01 | Approved NTP servers |
| SG-C0015T073V01 | Approved Syslog servers |
| SG-F1819T073V01 | Audit log retention |
| SG-C0001T073V01 | Audit logging status |
| SG-M4108T073V01 | Audit settings |
| SG-F3569T073V01 | Authentication server configuration |
| SG-F6881T073V01 | Authentication server redundancy |
| SG-F6469T073V01 | Authorization policy status |
| SG-M9375T073V01 | Browsable share status |
| SG-M2944T073V01 | CEE forwarding to external file policy server |
| SG-M5444T073V01 | Central Certificate Authority (CA) status |
| SG-C0029T073V01 | Centralized log server |
| SG-C0233T073V01 | Centralized log server redundancy |
| SG-M3812T073V01 | Certificate issuer |
| SG-M1335T073V01 | Certificate thumbprint algorithm |
| SG-M4279T073V01 | CIFS share user access list |
| SG-C0187T073V01 | CIFS SMB allowed access list - Host ACL |
| SG-C0187T073V02 | CIFS SMB allowed access list - RW |
| SG-C0188T073V01 | CIFS SMB configured ACL |
| SG-C0189T073V01 | CIFS SMB denied access list |
| SG-C0343T073V01 | CIFS SMB encryption (policy) |
| SG-C0190T073V01 | CIFS SMB external accounts ACL (access control list) |
| SG-C0122T073V01 | CIFS SMB version enabled |
| SG-M8868T073V01 | Cluster join mode |
| SG-M7230T073V01 | Configuration backup |
| SG-M1708T073V01 | Configuration change auditing |
| SG-C0065T073V01 | Data at-rest encryption |
| SG-F7757T073V01 | Data in-transit encryption |
| SG-F8349T073V01 | Data retention period |
| SG-M2688T073V01 | Data/Backup Retention |
| SG-M4840T073V01 | Default encryption enabled |
| SG-C0056T073V01 | Default passwords |
| SG-C0057T073V01 | Default passwords last change |
| SG-C0137T073V01 | Disable inactive users |
| SG-C0243T073V01 | DNS server configuration |
| SG-C0060T073V01 | DNS server redundancy |
| SG-M6167T073V01 | DNS service status |
| SG-M9803T073V01 | Drive firmware |
| SG-M8931T073V01 | Email notifications |
| SG-C0600T073V01 | End of support |
| SG-M8713T073V01 | Event forwarding to CEE |
| SG-F1313T073V01 | Event log retention |
| SG-C0162T073V01 | Expired SSL certificate |
| SG-M4205T073V01 | External firewall configuration |
| SG-M4080T073V01 | File share user access rights |
| SG-F5224T073V01 | Firewall rules configured |
| SG-C0195T073V01 | Firewall status |
| SG-C0380T073V01 | FTP service status |
| SG-C0600T073V02 | Future end of support |
| SG-M3840T073V01 | Guest account is disabled |
| SG-C0179T073V01 | Hardening status |
| SG-M1345T073V01 | HDFS access |
| SG-F3542T073V01 | HDFS service status |
| SG-M6631T073V01 | HTTP access |
| SG-F5506T073V01 | HTTP firewall rule |
| SG-F3553T073V01 | HTTP service status |
| SG-M3561T073V01 | Idle session timeout (CLI) |
| SG-F4591T073V01 | Idle session timeout (HTTP) |
| SG-M8767T073V01 | Idle session timeout (SSH) |
| SG-F9923T073V01 | Inactive users disabled |
| SG-M6287T073V01 | IPMI default password |
| SG-M4747T073V01 | IPMI IP ACL |
| SG-M1327T073V01 | IPMI power control |
| SG-M9698T073V01 | IPMI Serial over LAN |
| SG-M2580T073V01 | IPMI status |
| SG-M4010T073V01 | IPMI user list |
| SG-M4061T073V01 | Kerberos authentication status |
| SG-M6328T073V01 | KMIP status |
| SG-C0049T073V01 | KMS server configuration |
| SG-F9524T073V01 | KMS server redundancy |
| SG-C0039T073V01 | LDAP server configuration |
| SG-C0025T073V01 | LDAP server redundancy |
| SG-C0040T073V01 | LDAP service status |
| SG-F1732T073V01 | Locked (immutable) snapshots |
| SG-C0509T073V01 | Log forwarding |
| SG-M1404T073V01 | Log retention period |
| SG-C0427T073V02 | Login banner message - SSH |
| SG-C0426T073V02 | Login banner status - SSH |
| SG-C0234T073V01 | Maximum password age |
| SG-F2546T073V01 | Maximum user inactivity days |
| SG-F6304T073V01 | MFA bypass right assigned |
| SG-C0392T073V01 | Minimum account lockout duration |
| SG-C0262T073V01 | Minimum password age |
| SG-C0264T073V01 | Minimum password length |
| SG-M2032T073V01 | MOTD message |
| SG-C0428T073V01 | MOTD message - GUI |
| SG-M4919T073V01 | MOTD status |
| SG-C0423T073V01 | MOTD status - GUI |
| SG-C0239T073V01 | Multi-factor authentication |
| SG-M4852T073V01 | NDMP password strength |
| SG-M2172T073V01 | NDMP status |
| SG-M1776T073V01 | NFS access |
| SG-C0191T073V01 | NFS export ACL status |
| SG-M1059T073V01 | NFS export client access list |
| SG-C0121T073V01 | NFS versions enabled |
| SG-C0131T073V01 | Nobody user status |
| SG-C0230T073V01 | Non-default local admin |
| SG-C0231T073V01 | Non-default local users |
| SG-F7690T073V01 | NTLMv2 only |
| SG-M7603T073V01 | NTLMv2 status |
| SG-M1216T073V01 | NTP authentication |
| SG-C0171T073V01 | NTP server configuration |
| SG-C0432T073V01 | NTP server redundancy |
| SG-F6814T073V01 | NTP service status |
| SG-M1225T073V01 | OCSP configuration |
| SG-C0274T073V01 | Password complexity |
| SG-F9561T073V01 | Password hash type |
| SG-C0284T073V01 | Password history |
| SG-M3748T073V01 | Password last change |
| SG-C0293T073V01 | Protected recovery copies |
| SG-M5231T073V01 | Protocol auditing |
| SG-M3426T073V01 | Ransomware defender configuration |
| SG-M3300T073V01 | Ransomware file filtering |
| SG-M5299T073V01 | Reject unencrypted access |
| SG-M2212T073V01 | Remote copy |
| SG-M4728T073V01 | Remote replication configuration |
| SG-C0397T073V01 | Remote support configuration |
| SG-C0138T073V01 | Remote support status |
| SG-C0091T073V01 | Replication link encryption |
| SG-C0438T073V01 | Required Active-Directory provider |
| SG-C0054T073V01 | Required antivirus server |
| SG-C0450T073V01 | Required DNS servers |
| SG-M6740T073V01 | Required external syslog servers |
| SG-C0441T073V01 | Required identity provider servers - Kerberos |
| SG-M2156T073V01 | Required LDAP provider |
| SG-C0439T073V01 | Required LDAP servers |
| SG-C0014T073V01 | Required NTP servers |
| SG-C0016T073V01 | Required Syslog servers |
| SG-C0310T073V01 | Root user status |
| SG-M6311T073V01 | S3 service status |
| SG-C0071T073V01 | SED node status |
| SG-C0447T073V01 | Self-signed certificate |
| SG-F9235T073V01 | Session limit |
| SG-M9594T073V01 | SmartLock domains |
| SG-M9243T073V01 | SmartLock mode |
| SG-M2025T073V01 | SmartLock status |
| SG-M8461T073V01 | SMB access |
| SG-M2428T073V01 | SMB Encryption |
| SG-M5929T073V01 | SMB Security Signatures |
| SG-F1774T073V01 | SMB signing |
| SG-M2533T073V01 | SMBv1 status |
| SG-M2664T073V01 | SMBv2 status |
| SG-M1295T073V01 | Snapshot access |
| SG-M8357T073V01 | Snapshot autodelete |
| SG-M1426T073V01 | Snapshot configuration |
| SG-M1068T073V01 | SNMP agent Status |
| SG-C0058T073V01 | SNMP community default string |
| SG-M9940T073V01 | SNMP message privacy |
| SG-M3351T073V01 | SNMP message privacy algorithm strength |
| SG-M1808T073V01 | SNMP monitoring |
| SG-C0155T073V01 | SNMP service disabled |
| SG-M8218T073V01 | SNMP status |
| SG-M5535T073V01 | SNMP user authentication |
| SG-M8577T073V01 | SNMP user authentication algorithm strength |
| SG-M9679T073V01 | SNMP user permission |
| SG-C0123T073V01 | SNMP versions enabled |
| SG-M6412T073V01 | SNMPv1 / SNMPv2 status |
| SG-C0422T073V04 | SNMPv3 privacy encryption algorithm |
| SG-F1154T073V01 | SNMPv3 Security level |
| SG-C0419T073V01 | SNMPv3 user authentication protocol |
| SG-C0346T073V01 | SNMPv3 user security - Security-level |
| SG-F8167T073V01 | SSH connection session limit |
| SG-C0255T073V01 | SSH MAC strength |
| SG-F5351T073V01 | SSH root login |
| SG-M2182T073V01 | SSL certificate status |
| SG-M5138T073V01 | Support NetBIOS |
| SG-M1343T073V01 | Swift access |
| SG-M1110T073V01 | SyncIQ status |
| SG-M1932T073V01 | Syslog facility |
| SG-M3991T073V01 | Syslog min severity |
| SG-M3539T073V01 | System and data access zone separation |
| SG-C0019T073V01 | Target OS version |
| SG-M8568T073V01 | Telemetry status |
| SG-M4508T073V01 | Telnet access |
| SG-F9770T073V01 | Telnet service status |
| SG-M4696T073V01 | TLS level check |
| SG-C0448T073V01 | Trusted certificate-authority (CA) |
| SG-F8401T073V01 | Unapproved admin users |
| SG-F1494T073V01 | Unapproved user groups |
| SG-C0135T073V01 | Unknown user UID |
| SG-F6935T073V01 | Unused ports |
| SG-F4975T073V01 | USB ports disabled |
| SG-C0213T073V01 | Use of secure LDAP |
| SG-F1882T073V01 | User role configuration |
| SG-M1236T073V01 | Web-based access isolated to a specific management network |
| SG-C0108T073V01 | WORM Domain default retention |
| SG-C0109T073V01 | WORM Domain maximum retention |
| SG-C0110T073V01 | WORM Domain minimum retention |
| SG-C0111T073V01 | WORM Domain override retention date |
| SG-C0296T073V01 | WORM Domain privileged delete status |
| SG-M5556T073V01 | Zone Host ACL |
Related components
A complete baseline also covers the components that manage, connect to or protect Dell PowerScale. Review the configuration of:
- DataIQ and InsightIQ
- iDRAC (node management)
- Superna Eyeglass and Ransomware Defender
- Other PowerScale-related components
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.