User manual

Introduction
Features, Functions, and Options
1-6 July 2004 Wide Bank 28 DS3 - Release 2.4
With basic security, each user can be assigned a password. If security is on and passwords have
been assigned, the login process requires both a user name and password. Users can modify
their own passwords. If passwords have not been assigned, a user name is required but no
password.
When security is off, no password is required, and each user is considered to be at the admin
level.
Security Upgrade Option
The Wide Bank’s Security Upgrade option provides enhanced security features. In addition to
the features described for basic security, the Security Upgrade option provides:
One additional user access level (secu, described below)
Restrictions on the number and types of characters allowed in user names and passwords
The ability to set a time-out value for CLI sessions
The ability to individually disable the user interface ports: Ethernet port, 9-pin RS-232
CLI port, and 25-pin RS-232 TL1 port
The ability to disable SNMP management
The ability to disable TL1 management
The user access levels available with the Security Upgrade option are:
secu – The secu user has access to all commands and has the sole authority to grant others
access to the system by adding and deleting user names and passwords. The secu user
also has sole authority to perform such functions as clearing all statistics and logs,
configuring IP settings, restoring factory default or previously saved configurations, and
configuring the TL1 interface. There can be only one secu user within the system.
admin – An admin user has access to all commands except those assigned exclusively to
the secu user. Functions available to the admin user that are not available to lower-level
users include clearing DS1 and DS3 statistics, copying a configuration from the active to
standby Controller, setting the system time and date, programming the flash memory,
saving a configuration to a TFTP server file, setting various security functions,
configuring SNMP, and copying the current configuration to temporary storage.
rw (read/write) – An rw user has access to all commands except those assigned
exclusively to the secu and admin users. The rw users are typically responsible for the
day-to-day operation of the system.
ro (read only) – An ro user is limited to commands that display status and reports. The
ro access level permits technicians to monitor system operation and performance, but
prevents them from altering settings.
NOTE: In previous releases of the Wide Bank, the security access levels were Level 1,
Level 2, and Level 3. These levels correspond to secu, rw, and ro, respectively. If you are
upgrading firmware in a Wide Bank that supports the numerical access levels, the Level 1
user is automatically converted to secu; Level 2 users are converted to rw; and Level 3
users are converted to ro.