User`s guide

Table Of Contents
5-9
Basic Configuration
5.3.2. The Invalid Access Lockout Feature
When properly configured and enabled, the Invalid Access Lockout feature will watch all
login attempts made at the Network Port and serial Setup Port. If the port exceeds the
selected number of invalid attempts, then the port where the Invalid Attempts occurred
will be automatically disabled for a user-defined length of time (Lockout Duration.) The
lockout feature uses two separate counters to track invalid access attempts:
SetUpPortCounter: Counts invalid access attempts at the Setup Port. If the
number of invalid attempts at the port exceeds the user-defined Lockout Attempts
value, the port will be locked.
Telnet,SSHandWebBrowserCounter: Counts all invalid attempts to access
command mode via Telnet, SSH or Web Browser interface. If the number of
cumulative invalid attempts exceeds the user-defined Lockout Attempts value, then
the Network Port will be locked.
Note that when an Invalid Access Lockout occurs, you can either wait for the Lockout
Duration period to elapse (after which, the VMR/NPS will automatically reactivate the
port), or you can issue the /UL command (type /UL and press [Enter]) via the Text
Interface to instantly unlock all VMR/NPS logical network ports.
Notes:
When the Invalid Access Lockout Alarm has been enabled as described in
Section 7.6, the VMR/NPS can also provide notification via email, Syslog
Message, and/or SNMP trap whenever an Invalid Access Lockout occurs.
Invalid Access Lockout parameters, defined via the System Parameters
menu, will apply to both the Serial Setup Port and the Network Port.
When either the Setup Port or Network Port are locked, the other port will
remain unlocked, unless the Invalid Access Lockout feature has also been
triggered at that port.
If any one of the VMR/NPS logical network ports is locked, all other network
connections to the unit will also be locked.
Invalid access attempts at the Network Port are cumulative (the count for
invalid attempts is determined by the total number of invalid attempts at all
16 logical network ports.) If a valid password is entered at any of the logical
network ports, then the count for all logical network ports will be restarted.
If the Network Port has been locked by the Invalid Access Lockout feature, it
will still respond to the ping command (providing that the ping command has
not been disabled at the Network Port.)
In the Text Interface, the Invalid Access Lockout configuration menu is accessed via the
System Parameters menu. In the Web Browser Interface, the Invalid Access Lockout
configuration is accessed via the "General Parameters" link. The Invalid Access Lockout
configuration menus allow you to select the following:
LockoutEnable: Enables/Disables the lockout feature. (Default = On.)
LockoutAttempts: The number of invalid attempts required in order to activate the
Invalid Access Lockout feature. (Default = 9.)
LockoutDuration: The length of time that logical network ports will remain locked
when an Invalid Access Lockout occurs. If the duration is set at "Infinite", then ports
will remained locked until the /UL command is issued. (Default = 30 Minutes.)