System information
1-8 AR Series Router Reference Manual
Software Release 2.0.1
C613-03018-00 REV A
■
Using the command:
LOGIN
from any port or Telnet session to login under a login name that has
MANAGER privilege. The command prompts for a login name and
password. The password is case-sensitive and must be entered exactly as
defined. If the password is entered correctly, the port or Telnet connection
gains MANAGER privilege and the prompt changes to the MANAGER
level prompt. This is the usual method of gaining MANAGER privilege,
especially when managing remote routers.
■
Using the command:
SET MANAGER PORT
to set a particular port as a semipermanent MANAGER port. Any terminal
connected to the specified port will have MANAGER privilege. The SET
MANAGER PORT command on page 1-86 is a MANAGER level command
and can only be entered from a port or a Telnet session that already has
MANAGER privilege. Only one port at a time can be defined as manager
port.
To return to USER mode, use the command:
LOGOFF
Normally, the prompt changes when the user’s privilege level changes from USER to
MANAGER or vice versa. The prompt will not change if commands are being entered
from a terminal connected to a physical port and the port’s PROMPT parameter has
been changed to a user-defined string with the SET PORT command on page 2-32 of
Chapter 2, Interfaces.
The SECURITY OFFICER level has access to the full set of commands
regardless of whether the router is operating in normal mode or security mode.
When the router is operating in security mode, only users with SECURITY
OFFICER privilege can execute security commands (see Table 1-1 on page 1-5).
When the router is operating in normal mode MANAGER privilege is
equivalent to SECURITY OFFICER privilege. A user can only log in under a
login name that has SECURITY OFFICER privilege from either a terminal
directly connected to an asynchronous port on the router or a Telnet session
originating from an authorised IP address (see “Remote Security Officer” on
page 1-9).
A security timer operates while a user is logged in with SECURITY OFFICER
privilege, to minimise the risk of unauthorised access to an un-attended
terminal or Telnet session. Every time a security command is entered, the
security timer is restarted. If the timer expires the user’s privilege is reset to
MANAGER level, but the user remains logged in. Any attempt to execute a
security command will require the user to re-enter the SECURITY OFFICER
password. The timeout period, in seconds, can be configured using the
command:
SET USER SECUREDELAY=10..600