Artisoft			Technical Document


Title:		LANtastic Security
Updated:	01/97
Description:	Covers LANtastic in a DOS and/or Windows 3.x environment.  
Most apply to LANtastic in a Windows 95 environment as well.
FileName:	security.txt
FaxReturn#:	4054
Pages:		9


NOTE: Windows 95 uses a completely different control directory structure 
database.  There is no LANtasti.net directory but rather several database 
files.

OVERVIEW: This document outlines a step-by-step procedure for setting 
low,  medium and high levels of security in LANtastic Version 6.0 (and 
up).  Note  the basic scheme works for most, if not, all versions of 
Lantastic.  The  examples center around a hypothetical setup for 
Corporation XYZ  and its six employees.  You can derive any level of 
security from  the procedures in this document. 
 
Preliminary Procedure: To introduce security to a network, complete these 
preliminary  procedures: 
 
1.      Enable the Security Options: By default, the security features of 
LANtastic are "DISABLED".   To introduce security restrictions, do the 
following from the C:\  prompt: 
	CD\LANTASTI 
	NET_MGR.  (This launches LANtastics Network Manager)
	*       Select Server Startup Parameters.  
	*       Select Security and Send ID.   
		There will be about 6 items that are set to  "ENABLED" or 
"DISABLED": 

Use F1 at this screen (Help) for explanations of each  option. You can 
enable the different options for various levels of  security restriction. 
The following examples refer to this  figure, and discuss options to 
enable. 
 
2.      Password-Protect NET_MGR [OPTIONAL] : When setting up security 
restriction in LANtastic, you can  password-protect the Network Manager 
program itself.  This is an  optional item that requires anyone who 
attempts to launch NET_MGR  to enter a security password to gain access.  
The password must  be typed in each time NET_MGR is launched. 
 
CAUTION: If  you forget this password, you must completely delete  the 
control directory (C:\LANTASTI.NET) and recreate it!  This  directory 
contains all the security information and account  names.  Basically, it 
means starting from the beginning with your  setup! 
 
To password protect the Network Manager, type the following from  the C:\  
prompt: 
 
*       CD\LANTASTI     and press the [ENTER] key. 
*       NET_MGR and press the [ENTER] key.       
*       Select: Password Maintenance.   
*       Enable Password protection and choose a password. 
 
Directory Structure of the Example Server Computer's Hard Drive: 
 
C:------| 
	|___DOS 
	|___LANTASTI 
	|___LANTASTI.NET 
	| 
	|___AUTOCAD 
	|         |________FILES 
	| 
	|___PT 
	     |________PAYROLL 
	     |________OTHER 
 
The Company Used in These Examples XYZ Corp. with 6 employees:  
 
	POSITION                 	NAME         	ACCOUNT NAME 
	Network Administrator:      	Richard         	SYSOP 
	The Boss:                       	Bob             
	BOSS 
	2 Engineers:                    	Tom             
	TOM 
					Ellen           	ELLEN 
	2 Accountants:                  	Ann (mgr.)      ANN 
					Chris           	CHRIS 
 
 
LOW SECURITY 
This section tells you how to set up a network with just enough  security 
to protect the server's root and C:\DOS directory from  accidental 
alteration. 
 
This is one step above no security at all.  Essentially, all  employees 
log in under the "*" Wildcard Account, except for the  Network 
Administrator, who assigns himself an individual account  called SYSOP.  
The SYSOP account has full access, while the "*"  account is locked out of 
the C-DRIVE resource, preventing  alteration of the server's root and 
other sensitive  subdirectories.  The name "SYSOP" is an example.  You can 
use any  account name you want. 
 
Define the Resources and Accounts on the Server 
Set up the resources on SERVER that you plan to have available  for the 
employees. 

The network administrator, Richard, wants to set up an individual  account 
for himself, called SYSOP. This account has the  additional privileges and 
access that an administrator needs.   Everyone else in the company logs in 
using the wildcard "*"  account, which has certain restrictions set up as 
shown below. 
 
1.      Accounts Setup 
From DOS prompt... 
*       Type C:\LANTASTI [ENTER]. 
*       Type NET_MGR [ENTER]. 
	A menu appears.  
*       Select Individual Account Management. 
	A small screen labeled "Individual Accounts" appears, empty by 
default. 
*       Press the [INSERT] key. 
	A window appears, prompting "Enter the Account Name:". 
*       Type in the name "SYSOP" and [ENTER].  (The name SYSOP is an  
example. You may 
         use another name if you want.) This is followed by more question 
windows: 
	"Enter a Password for This Account:"  Type in a password, if  you 
desire. 
	"Enter a Description for This Account:"   
	"Enter the Number of Concurrent Logins for This Account:"   
Default is one (1). 
	Once completed, the new account appears in the "Individual 
Accounts" window. 
	Press the [ENTER] key.  This shows account details. 
 
For the SYSOP account, Richard wants ALL privileges.  The SYSOP  should 
have full access to all computers and resources on the  network, with no 
restrictions.  In this detailed screen, there is  one field entitled 
PRIVILEGES:, followed by eight dashes.   
 
*       Use the cursor keys to rest the highlight bar on PRIVILEGES.  
*       Press the "A" key.  An "A" character appears where the first dash 
used to be.  This is a
         super privilege that allows the SYSOP account to supersede ANY 
restrictions on the 
         network.   
*       While there, press the "Q" key.  A "Q" appears in place of  
another dash.  This allows the 
         SYSOP account to view ALL print jobs despooling from print queues 
on the network.  
 
2.      Resources Setup 
From DOS prompt... 
*       Type C:\LANTASTI [ENTER]. 
*       Type NET_MGR [ENTER]. 
	A menu appears.  
*       Select Shared Resources Management. 
	A list of shareable resources appears. From this list, select 
"C-DRIVE" and press the 
	[ENTER] key.  
	A screen of details for this resource appears.  Find  "ACL list," 
where access restrictions 
	for different accounts are set for this resource.  Set the 
highlight bar on the "*"  account 
	and press the [F4] key. This disables ALL privileges  for ALL 
users.  
*       Next, press the [INSERT] key.  
	"Enter the Account Name:"       SYSOP 
	By default, SYSOP appears with all privileges enabled. 
*       Press [ESC] once to go back to the resources list. 
 		 
*       Press the [INSERT] key to create a new resource.  
	"Enter the Resource Name:"      ACAD 
	"Enter the true path:"          C:\AUTOCAD      (where AutoCAD is 
located) 
	Note: The ACL list for this resource contains a "*" group, with 
all privileges enabled by 
	default. 
*       Press the [INSERT] key to create a new resource 
	"Enter the resource name:"      PEACH 
	"Enter the true path:"          C:\PT           (where Peachtree 
Accounting is located) 
	Note: The ACL list for this resource contains a "*" group, with 
all privileges enabled by 
	default. 
 
Now there are two more resources in the server's list: ACAD and  PEACH.  
At all employees' workstations, a "redirection" must be  set up to use any 
of the server's resources.  This redirection  command occurs in the 
workstation's STARTNET.BAT file as a NET  USE command.  For example:      
NET USE G: \\SERVER\PEACH The NET USE redirection command above allows 
this user to switch  to a G: prompt, and access the contents of the 
Servers C:\PT  subdirectory, including all subdirectories. 
 
Here is an example of what the BOSS would need in his  STARTNET.BAT file 
to set up redirections for all the resources  we've discussed: 
 
	..... 
	REDIR BOSS LOGINS=2             	set machine name to BOSS 
	NET LOGIN \\SERVER BOSS         login to SERVER as BOSS 
	NET USE D: \\SERVER\ACAD       	drive D: now points to the  
ACAD resource 
	NET USE E: \\SERVER\PEACH       drive E: now points to the PEACH 
resource 
	..... 
 
MEDIUM SECURITY 
This section tells you how to limit employee access only to  programs and 
files pertinent to their department.  The BOSS wants  access to the 
resources of both departments. The SYSOP account  still has unlimited 
access. 
 
Set up the Resources and Accounts on the Server 
Set up the resources on SERVER that you plan to have available  for the 
employees.  This is slightly more involved than our  previous low security 
example.  This higher level of security  requires all users to log in and 
provide a password to gain  access to the network. 
 
1.      Setup Accounts 
*       Create the SYSOP individual account listed above. 
	NET_MGR 
	Select Individual Account Management 
	Press the [INSERT] key to create a new account 
	"Enter the Account Name:"               SYSOP 
	"Enter a password for the account:"     Richard 
	"Enter a description:"                  network administrator 
	"Enter the number a concurrent Logins:"    1 (default) 

After these questions are answered, the new account SYSOP appears  in the 
Individual Account list window on your screen.  The  highlight bar should 
be resting right on it.   

*       Press the [ENTER] key. This shows account details. For the SYSOP 
account, Richard    
         wants no restriction.  The SYSOP should have full access to all 
computers and resources on
         the  network, with no restrictions.  In this detailed screen,  
there is one field entitled 
         PRIILEGES:, followed by eight dashes.  Here, you have the option 
to enable or disable any 
         of eight account Privileges: A, Q, M, U, S, O, D, N. (Press the 
[F1] key in this section for 
         An explanation of each option).   
*       Use the cursor keys to rest the highlight bar on PRIVILEGES.  
*       Press the "A" key.  An "A" character appears where the first dash 
used to be.  This is a 
         super privilege that allows the SYSOP account to supersede ANY 
restrictions on the 
         network.   
*       While there, press the "Q" key.  A "Q" appears in place of  
another dash.  This allows the
         SYSOP account to view ALL print jobs despooling from print queues 
on the network.  
*       Press the [ESC] key once to return to the accounts list screen. 
*       Create all other accounts. 
*       Press [INSERT] to add another new individual account.  Do not 
enable ANY of the super-
         privileges for these other accounts.   See the beginning of this 
section for instructions. 
*       Remove the "*" account in "Wildcard Accounts." 
*       In NET_MGR select Wildcard Account Management from the main menu. 
The only 
         account listed is the "*" account.  
*       Highlight this account and press [DEL]. 
*       Press [ENTER] to delete.  This removes the ability to 	log 
in under any name.  Now, a user 
         MUST log in under one of the six defined accounts in Individual 
Account Management.  
*       Press the [ESC] key to return to the main menu. 
 
2       Set up Resources and their Included ACL Lists 
When in Shared Resources Management, highlight and press [ENTER]  on any 
resource. The "Access Control List" screen pops up with  detailed 
information about this resource. Here, each account can  be individually 
added and its access privileges controlled. 
 
*       Create the PEACH and ACAD resources as in the low security 
example. 
*       NET_MGR. Select Shared Resources Management.  
*       From the list of resources that appears, select "C-DRIVE" and 
press the [ENTER] key.  
*       Under "ACL list", set the highlight bar on the "*"  account and 
press the [F4] key. This 
         disables ALL privileges for ALL users.  
*       Next, press the [INSERT] key.  
*       "Enter the Account:"    SYSOP    
	SYSOP appears with all privileges enabled by default. 
*       Press [ESC] once to go back to the resources list. 
*       Press [INSERT] to create a new resource. You are asked to do the 
following: 
	"Enter the Resource Name:"      ACAD 
	"Enter the true path:"          C:\AUTOCAD 
	The new resource appears in the list, with the highlight bar 
resting on it.   
*       Press the [ENTER] key.   
	Under "ACL list", highlight the "*" account and press the [F4] key 
to clear all privileges. 
*       Press the [INSERT] key. 
	"Enter the name of account or ACL group:"       ENG 
	ENG appears in the list with all privileges.  Note that the 
Account ENG does not exist. 
	This is actually an ACL group that we will create shortly. 
*       Press [ESC] once to go back to the resources list. 
*       Press [INSERT] to create a new resource.  You are asked to do the 
following: 
	"Enter the resource name:"      PEACH 
	"Enter the true path:"          C:\PT 
	The new resource appears in the list, with the highlight bar 
resting on it.   
*       Press the [ENTER] key.   
*       Under "ACL list", highlight the "*" account and press the [F4] key 
to clear all privileges. 
*       Press the [INSERT] key. . You are asked to the following: 
	"Enter the name of account or ACL group:"       ACCTNG 
	ACCTNG appears in the list with all privileges.  Note that the 
Account ACCTNG does 
	not exist yet.  This is actually an ACL group that we will create 
in the next section. 
*       Press [ESC] twice to go back to the main menu. 
 
3.      Set up ACL Group 
*       Create the ACLs. 
*       From the NET_MGR main menu, select ACL Group Management. A blank 
screen appears 
         with the headings "Defined Groups" and "Members." 
*       Press [INSERT]. You are asked to do the following: 
	"Enter the name: "      ENG. 
	"Enter a description:"  Engineering access 
	The ACL group appears.  
*       Highlight it and press [ENTER]. A list of members, currently 
blank, appears. 
*       Press [INSERT]. A list of available individual accounts appears.   
*       Highlight and press [ENTER] on BOSS, TOM, and ELLEN.   
*       [ESC] back to the ACL group list. 
*       Repeat the previous steps to create another new ACL called ACC, 
containing the accounts 
         BOSS,  ANN, and CHRIS. 
 
HIGH SECURITY 
This section tells you how to create a setup that is similar to  the 
previous medium security section, with the addition of a few  of the more 
advanced and flexible security features of LANtastic  6.0.  These features 
include File-Level Security, Time of Day  Login Restrictions, and Password 
Expiration. 
 
Desired New Restrictions: 
*       CHRIS should not have access to PAYROLL subdirectory, but should 
have all other 
         access.  BOSS accidentally altered an AUTOCAD file in the FILES 
subdirectory, so he has
         requested  that his access to FILES be READ-ONLY. 
*       XYZ Corp.s management has requested that the SYSOP (Richard)  
set up some kind of
         restriction to disallow any use of the network over the weekends 
(Saturday and Sunday).  
         Richard  	will use LANtastics Time- of -Day Restrictions 
feature to accomplish this. 
*       The management also wants to set up a system in which an account's 
password requires
         renewal on a regular basis.   Richard decides to use the Password 
Expiration feature of  
         LANtastic to set up expiration after 30 days. 
        
2.      File Level Security: Amending the Resources Setup 
*       Set up the accounts, ACL Groups and resources as described in the 
Medium Security 
         section.  
*       Run NET_MGR.   
*       Select Shared Resources Management. 
*       Select the ACAD resource.  
*       Highlight "File Level Security" and press [ENTER]. 
	You are prompted to:    Enter the File Name: \ 
*       Type in AUTOCAD\FILES\...\.  
	Note: The ellipses and extra backslash at the end will include any 
nested subdirectories 
	underneath  C:\AUTOCAD\FILES, and their contents.  
*       Another window appears, listing "Account/Groups" and "ACL"s.   
	Press [TAB] to switch to this window. 
*       Press [INSERT] to add an account. 
*       Add BOSS.  Clear the ACL privileges using [F4] and type R, L, and 
E.  This gives BOSS  
         READ-ONLY access to the subdirectory C:\AUTOCAD\FILES\...\. 
*       Now perform the same procedure to accomplish the file-level 
	restrictions for CHRIS, within 
         the PEACH resource, for files in C:\PT\PAYROLL\...\ 
 
2.      Time-of-Day Login Restrictions Setup 
The ability to LOG into a server can be restricted to certain  hours 
and/or certain days of the week.  You can do this in  NET_MGR by selecting 
Individual Account Management, or Wildcard  Account Management, whichever 
applies, to examine the account you  want to change. 
 
For this example, we will restrict TOM, ELLEN, ANN, and CHRIS  accounts 
to Monday through Friday, 6:00am to 6:00pm each day. 
 
 
From the DOS prompt: 
 
*       Type CD\LANTASTI then press the [ENTER] key. 
*       Type NET_MGR then press the [ENTER] key. 
*       From the NET_MGR menu, select Individual Account Management. 
         All six defined individual accounts appear in a pop-up window. 
*       Use the cursor arrow keys to highlight TOM, then press the [ENTER] 
key. 
         Detailed information on Toms account appears in another pop-up 
window. 
*       Use the cursor down-arrow key to highlight Login Hours, then press 
[ENTER]. 
         A grid of days-of-the-week versus hours-of-the-day appears.   
	 
A diamond shape indicates a time of allowed login.  To disallow  that 
login, use the cursor keys to move the highlight block over  that diamond 
and press the [SPACE-BAR] key to toggle to a period  (.).  This indicates 
that you have disallowed a login attempt at  that time, on that day. The 
[DEL] and [INS] keys will also  disallow or allow Logins, respectively. 

*       To set TOM and the other accounts to disallow Logins for 6:00pm 
through 6:00am every 
         workday, and disallow Logins at any time on Saturday and Sunday, 
change all the pertinent 
         diamonds into periods (.).  Each diamond corresponds to a 30 
minute block of time. 
*       Perform these same steps for all four accounts that require 
Time-of-Day Login Restrictions. 
 
3.      Setting up Password Expiration for Accounts 
This feature sets a date in the future when the user is prompted  to renew 
his password.  Often companies use this feature as an  added safety 
measure.  If the same passwords are used for long  periods of time, word 
sometimes spreads as to what passwords  access certain accounts.  If the 
passwords are required to be  changed every 30 days, for example, then 
this is not as much of a  worry. 

Password Expiration Date is found on the same screen as the Login  Hours, 
as described in the previous Time-of-Day Restrictions  example. 

From the DOS prompt: 
*       Type CD\LANTASTI  then press the [ENTER] key. 
*       Type NET_MGR then press the [ENTER] key. 
*       From the NET_MGR menu, select Individual Account Management. 
	All six defined
         individual accounts appear in a pop-up window. 
*       Use the cursor arrow keys to highlight TOM, then press the [ENTER] 
key. 
	Detailed information on Toms account appears in another pop-up 
window. 
*       Select Password to set the password for the account. 
*       Select Password Expiration Date to set the date upon which renewal 
is required. 
*       Repeat these same steps for all accounts that need the password 
features enabled. 

Artisoft, Inc.
2202 N. Forbes Blvd			 
Tucson, AZ  85745		
				
Internet 
  web:				http://www.artisoft.com	
  ftp:				ftp.artisoft.com
FaxReturn: 			520-884-1397
ArtiFacts bbs:			520-884-8648 (8 bits,No parity,1 
stop bit)
Sales Consultation Center:  	(800) 846-9726  
			  FAX (520) 670-7359
Customer Service:	      	(800) 846-9726
Technical Support Information:	(520) 670-7000

ARTISOFT TECHNICAL SUPPORT
Artisoft offers a wide selection of technical support options.  For
information regarding technical support services, please refer to 
our Directory of Support Services, available where you obtained 
this Technical Note.
Check Technical Support & Services on our Home Web Page, 
request FaxReturn document 4, or download the file DIRLIST.TXT).  
You can also obtain this information by calling Artisoft at (520) 670-7000.

DISCLAIMER:

THIS INFORMATION MAY BE INTERNAL OR EXTERNAL TO ARTISOFT 
AND IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER 
EXPLICIT OR IMPLIED.  ARTISOFT DISCLAIMS ALL WARRANTIES AND 
SHALL NOT BE LIABLE FOR ANY SPECIAL, INCIDENTAL, CONSEQUENTIAL, 
INDIRECT, OR PUNITIVE DAMAGES, OR LOST PROFITS OR REVENUE, EVEN 
IF IT HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.  SOME 
STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR 
CONSEQUENTIAL OR INCIDENTAL DAMAGES, SO THE FOREGOING 
LIMITATION MAY NOT APPLY TO YOU.

Brand names, company names, and product names are trademarks of their 
respective companies.
