User guide
CLI Logins Tab Discovery Configurator (Service Provider)
3-7
AlliedView NMS Administration Guide (File Administration)
If all login attempts with matching hints fail, all of the entries without hints will be attempted until one is accepted or all are
rejected. And if all of those fail, all of the rest (without matching hints) will be attempted.
The Description field is a free format reminder of what each login entry represents.
There are 2 login types: User and Security Officer, which are specified by the radio buttons. The “user” type uses the User Id
and Password to initially log into the device. User login is all that’s required for iMAPs running without TACPLUS.
If an iMAP is running with TACPLUS enabled, the NMS also needs a Security Officer passcode (to enable securityofficer).
Security Officer passcodes can be designated by clicking on the Security Officer radio button. For Security Officer, the User
Id field is not applicable and will be disabled and set to “tacacs+”. (You can still define a user login with the user id tacacs+,
if necessary, by clicking on the User radio button instead of the Security Officer radio button) Security Officer passcodes
will be attempted as ordered in the list and as overridden by Hints. Since multiple Security Officer passcodes are permissi-
ble, be sure to use the description field to keep track of which is which (since they will typically be indistinguishable without
displaying the passcode).
Buttons specific to the CLI Login Manager are:
• Add - Adds a new entry to the CLI User list—after the current position of the selected login. (Duplicates are allowed)
• Modify - Overwrites the currently selected login with what’s in the main dialog.
• Delete - Deletes the currently selected login from the CLI User list.
Note: Discovery uses the CLI logins in the order specified in the CLI Login Manager. There is a performance hit
associated with each failed login attempt. Use the up/down keys to order the list such that the most likely
pair is listed first. (Use the Hints field to help identify device)
Caution: One feature for AT and iMAP devices is the ability to change their default prompts to a custom
string. (For AT devices the default prompt is “>”, and for iMAP devices this feature begins with
the default prompt “>>”.) Therefore, this default prompt should not be changed.
There is also the option to select the protocol. The default is telnet, but here is also the option to choose SSH. These are also
added to the User ID list.
Most Allied Telesis devices support SSHv2. Using SSH involves configuring and enabling the SSH server. This involves:
• Server authentication, confidentiality, and integrity
• User authentication through the use of a password and/or public key
• Connection encryption for interactive login sessions
Refer to customer documents for Allied Telesis products for support of specific SSH features.