PortaBilling/PortaSwitch includes multiple layers of security controls for server access, user authentication, password management, and network-level protection.
All third-party open-source and commercial components included in the PortaBilling/PortaSwitch product are maintained and updated by PortaOne.
When PortaOne Support needs to access a service provider’s installation for monitoring or troubleshooting, they connect via secured internal access servers using multi-factor authentication. All actions are logged, allowing service providers to review what was done and when.
At the network level, PortaSwitch servers can be placed behind a firewallthat permits connections only on required ports and from authorized IP addresses. Access can be further refined by blocking or explicitly allowing individual IP addresses using the IP blocklist/allowlist on the servers. SSH access is additionally protected against brute-force attacks.
For web access, PortaBilling supports two-factor authentication (2FA), which requires a time-limited one-time password in addition to login credentials. Password storage, complexity requirements, and expiration policies are covered in the Password protection chapter.