Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
246
Basic system management
213455-L, October 2005
For more details, see
VRRP Interface Menu on page 330
. Make sure management support
is enabled for the interface using the command,
/cfg/net/if#/mgmt/ena.
For details, see Nortel Switched Firewall
5100 Series BBI User’s Guide
(216383-D).
The Check Point Firewall-1 NGX interface
The Check Point interface is used for managing firewall policies, and for viewing firewall
logs and operational status. It is accessed through remote Check Point management
stations or clients. A Check Point management station is required during initial system
setup and for establishing firewall security policies, and monitoring policy effectiveness.
For details, see your Check Point documentation.
Users and passwords
Access to system functions is controlled through the use of unique usernames and passwords.
Once you are connected to the system through the local console, Telnet, SSH, or web browser,
you are prompted to enter a password. To enable better system management and user
accountability, four levels of user access have been implemented on the Nortel Switched
Firewall. The default user names and password for each access level are listed in
Table 5
. User
names and passwords are case sensitive.
N
OTE
–
Nortel recommends that you change all the default passwords after initial
configuration and as regularly as required under your network security policies. For more
information, see
User Menu on page 318
for CLI commands.
Table 5
User access levels
User Name Password
Description and Tasks Performed
oper
oper
The operator login is available through the CLI and BBI. The operator
has no direct responsibility for system management. He or she can view
all configuration information and operating statistics, but cannot make
any configuration changes.
admin
admin
The administrator login is available through the CLI and BBI. The
administrator has complete access to all menus, information, and configu-
ration commands on the system, including the ability to add users and
change passwords.
boot
ForgetMe
The boot login is available only through a local console terminal. The
boot user can reinstall the Firewall software (see y). To ensure that one
avenue of access is always available in case all passwords are changed
and lost, the boot user password cannot be changed.