Version 6.6
367
October 2014
Installation & Operation Manual
33. Configuring Security Settings
33.18.4
Synchronizing the CLI Users Database with the EMS Server
In the typical Media Gateway deployment scenario, the same users, passwords and
access levels are used for all available Media Gateway management interfaces –the
EMS GUI and the CLI.
To simplify user maintenance in such a scenario, the Media Gateway supports
synchronization of the CLI Users Database with the EMS server. When this
synchronization is activated, the Media Gateway will constantly synchronize its local
CLI users database with the users database on the EMS server. Any change to the
users database on the EMS server will be updated to all Media Gateways within a
short period of time. All EMS server user profile attributes, including the access level
and the password expiration policy are updated on both SC boards of all the Media
Gateways connected to the EMS server. Use of the local CLI database ensures that
the CLI users may access the Media Gateway even when there is no connectivity
between the Media Gateway and the EMS server (e.g. in case of a network failure).
Figure
33-5: Synchronizing CLI Users Database with EMS Server
33.18.4.1
Synchronization Modes
When the CLI Users Database is synchronized with the EMS server, all user
maintenance operations (user addition, removal and password change) must be
performed via the interfaces provided on the EMS server. See the EMS User Manual
for additional information. Only the passwords of
root
and
ems
users may be modified
locally on the SC boards via
tools user
script as described in the previous sections.
Enable Block Mode
In this mode, CLI users whose passwords have expired are immediately denied
access to the Media Gateway’s CLI; in case of a network outage this means that
some CLI users may be unable to access the CLI (if their passwords expire at the
time of the outage).
Enable Seven Days
In this mode, CLI users whose passwords have expired are allowed access to the
Media Gateway’s CLI for an additional 7 days; this period is counted starting from
the first user login after the password expiration; within these 7 days, users
should access the EMS GUI and enter new passwords; users who do not renew
their passwords within 7 days are denied access to the Media Gateway’s CLI.
Summary of Contents for Mediant 8000
Page 2: ......
Page 33: ...Part I Hardware Overview This part describes the hardware overview of the Mediant 8000 chassis...
Page 34: ......
Page 90: ......
Page 158: ......
Page 264: ......
Page 546: ......
Page 775: ...Part VI Maintenance This part describes the Mediant 8000 maintenance procedures...
Page 776: ......
Page 834: ......
Page 879: ...Part VIII Appendices This part describes additional Mediant 8000 configuration procedures...
Page 880: ......
Page 924: ...Media Gateway Mediant 8000 www audiocodes com Installation Operation Maintenance Manual...