Installation and Operation Manual
Chapter
1 Introduction
ACE-3105, ACE-3205 Ver. 5.2
Functional Description
1-29
Figure
1-23. Ethernet to ATM VC Subnet Conversion
Management Security
Access via terminal, Telnet or ConfiguRAD is password-protected and can be
secured using SSL protocol or SSH-based client/server connection. The system
logs out automatically and displays the login screen after 15 minutes of inactivity
(time during which no character was sent to the terminal/Telnet).
After three unsuccessful login attempts, ACE-3105, ACE-3205 locks up and
prohibits additional attempts for 15 minutes. Any attempt to log into ACE-3105,
ACE-3205 (valid or invalid attempt) results in sending events/traps to the log file
or NMS.
Three user access levels are supported:
•
su – super user, full read and write access, not including access to hidden
screens for internal/debugging use.
•
tech –limited write access to alarm configuration, clearing of alarms and
access to diagnostics.
•
user –read-only.
SNMP (simple network management protocol) version 3.0 adds security and
remote configuration capabilities to the previous versions (SNMPv1/SNMPv2).
This includes:
•
Message integrity –ensuring that a packet has not been tampered with during
transit
•
Authentication –determining that the message originates from a valid source
•
Encryption – scrambling the contents of a packet prevent interception by
unauthorized sources
•
Security models – authentication strategies that are applied on single users
or entire user groups
•
Security levels – set the permitted level of security within security models.
A chosen combination of a security model and a security level determines which
security mechanism is employed when handling SNMP packets.