Appliance Security Considerations
AROVA appliances are deployed inside the Google Cloud infrastructure and cannot be directly accessed from external networks. IAP port forwarding can be used to allow selected users access to deployed AROVA. HTTP access over internal networks and SSH access to appliances is also possible.
- It is recommend to create a dedicated project with access limited by IAM for AROVA deployment.
- In addition to controlling access to AROVA appliances with IAM/IAP, a separate password-based authentication method has been implemented for further separation of access.
- The password is set when the deployment script is executed.
- Logging into AROVA UI:
- Use the username: "admin"
- Enter the password that was specified during deployment.
- SSH access to the AROVA appliance also requires the admin user’s password.
- After 60 days, AROVA requires the password to be changed. Prior to the deadline, the system will begin posting warning messages to the Google Event Console reminding you to update the password.
Note: To change the admin access password, log into AROVA and execute the command: sudo passwd admin.