User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Mesh Point CLI and Administrative Access
12
Angle brackets: indicate variable, user-supplied inputs
(parameters and variable arguments), which are also
italicized (ex.,
<sharedkey>, <port1,port2,...>).
The absence of angle brackets and italics indicates literal
(or fixed) user-supplied input (ex.,
y|n
).
Pipes are placed between mutually exclusive arguments
(ex.,
y|n
).
An ellipse indicates than the argument can include more
entries of the same kind (ex.,
<port1,port2,...>).
A hyphen indicates an allowable range; ranges are
expressed inclusively (ex.,
1–4094
)
Many of the commands that change Mesh Point configuration
settings can be run interactively: when you enter a command
with one of its options, the parameters that can be configured
through the command display as user-navigable or
consecutively presented fields. Refer to the examples given in
the instructions below.
2.2 Administrative Accounts and Access
NOTE: The precon-
figured admin
account corresponds to
the Crypto Officer role as
defined by Federal
Information Processing
Standards (FIPS) 140-2
Security Level 2.
Up to ten usable administrative accounts can be present in the
Mesh Point’s local administrator database, used to
authenticate administrators with locally configured
administrative accounts.
View a summary of the local administrator authentication
database with
show admin:
# show admin
Administration Accounts
------------- --------
Total admin users 3
Total administrators 1
Total maintainers 1
Total log viewers 1
By default, three accounts are preconfigured on the Mesh
Point, one at each of the three possible privilege levels:
administrator accounts have full privileges.
NOTE: Provided
the password is
not locked (Section
2.2.3), administrators
with maintenance or
logviewer accounts
can change their own
passwords (Section
2.2.4).
maintenance accounts have full view-only privileges and
can reset connections, reboot the Mesh Point, create
support packages, and execute
ping and traceroute.
logviewer accounts have limited view-only privileges
exclusive to the system log, excluding logged configuration
information.
Only one Administrator-level account can be active on the
Mesh Point at one time. Their limited permissions allow
multiple Maintenance-level and Log Viewer-level accounts to
be active on the Mesh Point at the same time. Only one active