CHAPTER 4 Functions provided by the PRIMEQUEST 2000 series
4.2 Management with MMB
80
CA92344-0534-07
FIGURE 4.3 Access to MMB in global user management (LDAP is enabled)
Note
If you use Local user management, you cannot login MMB by the user account registered in external LDAP
server.
If you use Global user management, you cannot login MMB by the user account registered in MMB.
Before you enable LDAP function, you must create special account in MMB. Special account is used to login
MMB if LDAP server fails or error occurs in network path including the LDAP server.
For MMB Web-UI windows related to LDAP, see ‘Chapter 1.4.4 [LDAP Configuration] window’ of the
“
PRIMEQUEST 2000 Series Tool Reference
” (CA92344-0539).
For setting of LDAP, see ‘3.6 Setting of LDAP’ of the
PRIMEQUEST 2000 Series Installation Manual
(CA92344-0536).
4.2.4 MMB operating environment
This section describes the security in the MMB operating environment.
SSL support
The MMB encrypts Web and telnet access using SSL (Secure Sockets Layer). It creates secret keys and
electronic certificates.
Remarks
The MMB is provided with interfaces, such as telnet and the Web-UI and also manages their system
accounts. The MMB can be configured redundantly, so that the information specified for the Active side can
be passed on to the Standby side.
Access control
To ensure security, the IP filter that permits access to MMB is set. The IP addresses that can be used are
set for each protocol, and only those IP addresses can access the MMB.
MMB operator privileges
MMB Web-UI menu reference and operator privileges can be set for each user. For details on the security
settings for MMB operating environment, see ‘6.5 Configuring Security’ of the
PRIMEQUEST 2000 Series
Installation Manual
(CA92344-0536).
For details on the operator (user) privileges for the MMB operating environment, see ‘Chapter 1 Web-UI
(Web user interface) operation’ of the “
PRIMEQUEST 2000 Series Tool Reference
” (CA92344-0539).