Admin Guide

Table Of Contents
Important:
When you enable RADIUS on the switch and configure a RADIUS server to be used by CLI or
EDM, the server authenticates the connection, whether it is FTP, HTTPS, SSH, or TELNET.
However, in the event that the RADIUS server is unresponsive or is unreachable, the switch will
fall back to the local authentication, so that you can access the switch using your local login
credentials.
If you disable an access level, all running sessions, except FTP sessions, with that access level to
the switch terminate.
Important:
Only the RWA user can disable an access level on the switch. You cannot disable the RWA
access level on the switch.
The system preserves these configurations across restarts.
hsecure bootconfig flag
The switch supports a configurable flag called high secure (hsecure). Use the hsecure flag to enable
the following password features:
10 character enforcement
aging time
limitation of failed login attempts
protection mechanism to filter designated IP addresses
If you activate the hsecure flag, the software enforces the 10-character rule for all passwords. The
password must contain a minimum of two uppercase characters, two lowercase characters, two
numbers, and two special characters.
If you enable hsecure for the first time and the password file does not exist, then the device creates
a normal default username (rwa) and password (rwa). In this case, the password does not meet the
minimum requirements for hsecure and as a result the system prompts you to change the password.
For more information about the hsecure flag, see Configuring Security on Avaya Virtual Services
Platform 7200 Series and 8000 Series, NN47227-601.
Enhanced secure mode
If you enable enhanced secure mode, the system uses different authentication levels. Enhanced
secure mode allows the system to:
Provide role-based access levels
Stronger password requirements
Stronger rules on password length
Stronger rules on password complexity
Stronger rules on password change intervals
Stronger rules on password reuse
Stronger password maximum age use
For more information on enhanced secure mode, see
System access security enhancements on
page 196.
System access
January 2017 Administering Avaya VSP 7200 Series and 8000 Series 180
Comments on this document? infodev@avaya.com