Advanced Simulation Technology inc.
ASTi Standard Telestra 3 Platform

Telestra 3.x Software

The Telestra platform is supplied with a removable hard drive, which allows a user to physically remove the Telestra hard drive. This allows the end customer to separate users and/or security levels with different physical hard drives. The drives can also be removed after an exercise and stored in a secure location.

General Technical Security Statement

  1. ASTi's Telestra systems are capable of storing digital voice communications audio. ASTi's communications simulation software toolkit, Model Builder Visual, includes a sound recording feature that when enabled may be used to create and playback digitized audio sound files, which are stored on the system hard drive (or flash disk, if applicable). Digital sound recording is a user configurable feature. Note that some of these features rely on a software version that supports that feature set. The software version may not currently be available. Contact ASTi for the latest software features available.

  2. ASTi systems contain non-volatile, non-protected memory (BIOS EEPROM, for example). Therefore, end user security authorities are advised to follow standard security operating precautions to safeguard the systems against unauthorized access.

  3. ASTi systems are not designed to meet, nor tested for compliance with TEMPEST standards.

User Accounts

There are two types of user accounts on the Telestra 3.0 system:
  • RMS Users
    This type of user account grants access to Telestra's web-based RMS interface only. RMS users do not have any additional access to the Telestra system. They cannot log into Model Builder Visual, nor can they log into the Telestra system's Linux console or access the system via SSH.

  • System-Level Users
    This type of account is a standard Linux (or Unix) user account. These users can access the Telestra system via the Linux console and SSH. They can also log into Xwindows and launch Model Builder Visual. Model development can only be performed by system-level users. System-level users do not have access to the RMS interface.
Both types of accounts can be created through RMS.
During software installation a few default user accounts are created, and additional accounts can be created as required. See the Telestra 3.0 User Guide (DOC-01-TELS-UG-3) for user account names, default passwords, and capabilities. For security purposes, the default passwords should be modified and recorded using customer-specific procedures.
Consult the Linux documentation on user accounts for more information.

Remote Access Services

The Telestra platform has the ability to run various servers that provide remote access to the system. These include: SSH/SFTP, HTTP/HTTPS and DHCP servers. See the Telestra 3.0 User Guide (DOC-01-TELS-UG-3) for information about each of these.
HTTP (web) and HTTPS (secure web) access should not be disabled unless absolutely necessary. Without RMS access to the Telestra, a user will have no visibility into the status, health, configuration, etc. of the machine. SSH can be disabled if Secure Shell remote access is not required for the system.
Note that HTTP/HTTPS access to Telestra 3 systems requires "RMS User" authentication (e.g., username and password). There is no access to RMS' web pages without this authentication.
See the links in the right-hand sidebar for more information on Telestra hardware and software.