Troubleshooting guide
2 — 5620 SAM user security
Alcatel-Lucent 5620 Service Aware Manager 2-15
5620 SAM
System Administrator Guide
3 Create scope of command roles or modify the default role to meet your
operational requirements; see Procedure 2-2.
4 Create scope of command profiles that contain the appropriate scope of command
roles for the types of tasks to be performed; see Procedure 2-3.
5 Create spans or modify the default span to meet your operational requirements.
Add 5620 SAM managed objects to the spans; see Procedure 2-4.
6 Create span of control profiles that contain the required spans; see Procedure 2-5.
7 Create span rules, as required, to automatically assign new services to spans other
than the Default Service Span; see Procedure 2-6.
8 Manage user group security requirements, as required.
• Create or modify user groups and assign scope of command and span of control
profiles to each group, as required; see Procedure 2-7.
• Add workspaces to user groups; see Procedure 2-8.
• Add access permissions to the 5620 SAM applications for a user group; see
Procedure 2-9.
9 Create, modify, or copy user accounts for performing the tasks that are associated
with each user group; see Procedures 2-10 and 2-11.
10 Configure global user account parameters, as required.
• user-account expiry periods, password criteria, and a GUI inactivity timeout;
see Procedure 2-12 and 2-13.
• minimum username length; see Procedure 2-14.
• allowed number of authentication attempts; see Procedure 2-15.
• suspended account actions; see Procedure 2-16.
• automated e-mail notification; see Procedure 2-17.
11 Configure global user activity logging, as required; see Procedure 5-24.
12 Enable and configure 5620 SAM access for remote users, if required.
i Configure authorization for remote users in which either the 5620 SAM or the
remote authentication server associates the user with a user group:
• for LDAP: Procedure 2-33
• for RADIUS: Procedure 2-34
• for TACACS+: Procedure 2-35
ii Configure the general remote-access parameters, and specify LDAP, RADIUS,
and TACACS+ servers, as required; see Procedure 2-36.
Release 13.0 R2 | May 2015 | 3HE 09815 AAAB TQZZA Edition 01