363-206-295
Administration and Provisioning
8-2
Issue 1
December 1997
Security
8
DDM-2000 OC-12 Multiplexers provide security capabilities to protect against
unauthorized access to the system through the CIT, data communications channel
(DCC), and TL1/X.25 interfaces. When security is enabled (default is disabled for
the CIT and DCC and always enabled for TL1/X.25), four types of users are
allowed access to the system with a valid login and password:
■
Privileged users can execute all commands
■
General users can execute any commands not restricted to privileged
users
■
Maintenance users can execute some of the general level and all “reports-
only” commands that are not restricted to priviliged users
■
Reports-only users can only execute commands that retrieve reports from
the system.
When the system is first initialized, three default logins and passwords are
provided which must be changed by a privileged user before security is enabled.
At initialization, privileged users are those users who use the default logins and
passwords. Replacement of the SYSCTL circuit pack causes the system to default
back to the default logins and passwords. Up to 100 logins and passwords can be
added, deleted, and changed by three authorized privileged users. Login and
password security can be enabled or disabled. Timeouts can be provisioned
independently for front and rear access CIT interfaces and the synchronous
optical network (SONET) section DCC. Timeout is disabled on the TL1/X.25
interface. For more information on provisioning, see “System Turnup/Circuit
Order,” in the TOP section of this manual (Volume II).
Authorized privileged users can establish general user and reports-only user
logins using the
set-lgn
command. Authorized privileged users can also
"lockout" access by general and reports-only users without deleting the login and
password file.
The following commands are restricted to privileged users over the CIT and DCC
interfaces. See 824-102-151,
DDM-2000 Multiplexers Operations Systems
Engineering Guide for TL1/X.25 command access privileges.
■
init-sys
— Initialize System
■
rstr-passwd
— Restore login and password file
■
rtrv-lgn
— Retrieve Login
■
rtrv-passwd
— Retrieve login and password file
■
set-feat
— Set Features
■
set-fecom
— Set Far-End Communications