Instruction manual

Special security product and service offers
16-4 Issue 9 May 2003
Avaya support
Avaya provides RPSD keys to their maintenance centers to accommodate access
to systems you secure with the RPSD lock.
For more information on the RPSD, see the DEFINITY® Communications
Systems Remote Port Security Device User’s Manual.
Securing DEFINITY systems
(Release 7.2 and Later) with Access
Security Gateway
The Access Security Gateway (ASG) integrates challenge/response technology
into Avaya products and is available, beginning with the DEFINITY ECS Release
7.2 (that is, DEFINITY G3V7.2), to secure the DEFINITY switch administration
and maintenance ports and logins and thus reduce the possibility of unauthorized
access to the system.
The challenge/response negotiation starts after you have established an RS-232
session and have entered a valid Communication Manager, MultiVantage™
Software, or DEFINITY ECS login ID. The authentication transaction consists of a
challenge, issued based on the login ID that you have just entered, followed by
the expected response, which you must enter. The core of this transaction is a
secret key, which is information-possessed by both the lock (ASG) and the key.
Interception of either the challenge or response during transmission does not
compromise the security of the system. The relevance of the authentication token
used to perform the challenge/response is limited to the current
challenge/response exchange (session).
Currently-supported keys consist of a hand-held token generating device (ASG
key). The ASG key (response generator) device is pre-programmed with the
appropriate secret key to communicate with corresponding ASG-protected login
IDs on Communication Manager, MultiVantage™ Software, and DEFINITY ECS.
ASG administration parameters specify whether access to the system
administration or maintenance interface requires ASG authentication. This
security software can be assigned to all system administration maintenance ports
or to a subset of those ports. If the port being accessed is not protected by ASG,
the standard DEFINITY login and password procedure will be satisfactory for the
user to enter the system.
For more information about Access Security Gateway and required ASG forms,
see the Administrator’s Guide for Avaya™ Communication Manager,
555-233-506.
NOTE:
ASG does not protect login access to a multiple application platform for
DEFINITY (MAPD).