Securing Your Deployment

Security-related configuration in NetXMS spans several subsystems — user authentication, certificates, agent communication, and script execution. This page maps the security controls available to you and links to the pages that describe each in detail. It introduces each area briefly; the linked pages are the authoritative descriptions.

For the architectural view of how components authenticate and encrypt traffic between each other, see the Security section of the Architecture page.

User Accounts and Authentication

Access to the server is controlled through users, groups, and system access rights, described in User Management. The controls most relevant to hardening:

  • Password policy — minimum length, complexity requirements, expiration, and history are governed by server configuration variables. See Password Policy and the Password Policy Variables reference.

  • Two-factor authentication — TOTP and message-based second factors can be configured system-wide and enforced per user or group. See How to Configure Two-Factor Authentication.

  • External authentication — LDAP, RADIUS, CAS, and certificate-based user authentication offload credential management to existing infrastructure. These are covered in User Management and Certificate Management.

  • UI access rules — restrict which parts of the management client a user can see, independently of object permissions. See How to Configure UI Access Rules.

  • Authentication tokens — tokens used for API and integration access have their own lifecycle and revocation controls. See Authentication Tokens.

Object-level permissions determine what an authenticated user can do with each part of the object tree; see Managing Objects.

Certificates and Encrypted Communication

The server uses TLS certificates for agent tunnels and can authenticate both agents and users with certificates. Certificate Management covers server certificates, automatic certificate issuance for tunnel-bound agents, manual provisioning, and troubleshooting.

Agent-to-server communication security has two layers:

  • Transport encryption — agent connections are encrypted by default; the available ciphers and the encryption policy are described in Agent Configuration: Authentication and Encryption.

  • Authentication — agents restrict which servers may talk to them through IP-based access lists (MasterServers, ControlServers, Servers), optionally combined with a shared secret and server certificate verification. See Server Access Control and the Access Level Matrix for what each access level permits.

For agents behind NAT or firewalls, Agent Tunnels provide agent-initiated TLS connections with certificate-based agent identity.

Script Execution

NXSL scripts run inside the server and can read and modify monitored objects, so script permissions matter. The trusted-node model and script access control are described in Script Security in the NXSL Reference; the server-side execution context is summarized in Scripting Overview: Execution Security.

Agent-side command execution (external metrics, actions) has its own risk profile — in particular, shell form versus exec form and the handling of metric arguments. See External Metrics, Actions, and Data Providers.

Audit Logging

The server records administrative actions in an internal audit log and can forward audit records to an external syslog receiver. See How to Configure Audit Logging and Audit Log Forwarding.

Platform Hardening

Installation pages carry platform-specific security notes — file permissions, service accounts, and firewall configuration:

Security-related server configuration variables are listed in the Server Configuration Variables reference.