1 . Web Mgmt Interface - Use stunnel Passwords are NOT sent as clear text, a CHAP protocol is used making standard user authentication safe over http. HOWEVER, the user administration screens that change/set passwords send md5 encoded passwords over the wire thus giving an attacker a chance to get the encoded password which could potentially be used (with some special code) to get an authenticated login. If this is an issue, configure the server running the Aware webserver to use stunnel to expose an https port for access and have it pass the packets back to the unencrypted port. 2. Aware "Slave" Agents Communicating Aware "slave" agents receive their configuration files from the "master". This is an unencrypted transfer. Also, Aware agents may relay events back to the "master" via an unencrypted message. If this is a concern, you should do one or all of the following: - Create a separate independent network for monitoring (this could be a VPN) - Encrypt traffic network over monitoring network. Common utilities like ssh and stunnel make setting up encrypted tunnels very easy. Alternatively, lower level encrytpion is also possible with IPSEC.