Clearspan® Product Overview R19
Aastra – 2740-007
2014 Clearspan® is a Registered Trademark of Aastra Technologies Ltd.
Page 27 of 93
upon users. In turn, system administrators can specify the password requirements of the group and
provisioning administrators.
For added security, Clearspan provides a password wizard. Using the wizard, system
administrators can force users to change passwords on an incremental basis. Administrators can
also set up password rules that remove trivial patterns and repeated passcodes. A specified
number of unsuccessful login attempts blocks users or administrators from entering the system,
protecting against password guessing. When a user is blocked from the system, an e-mail
message is sent to an administrator, warning of the login attempt and subsequent block.
For the Application Server, Media Server, and Network Server, the
web interface
permits secure
access for the following:
Application Server
Media Server
Network Server
System administrator
Enterprise administrator
Group provisioning
administrator
Group administrator
End user
Not accessible by any user
type (CLI access only)
System administrator
Group provisioning
administrator
Enterprise administrator
(manages dial plan
information for specific
groups)
Clearspan inspects the source IP address of the packet and compares it to the IP address or
resolved hostname in the endpoint identifier contained in the message. If they match, the packet is
allowed and processed by the system. Otherwise, the packet is ignored and no further processing
is performed.
As a secondary level of security, Clearspan only allows hostnames or IP addresses in the endpoint
identified that have been configured in the access device list for a group. Therefore, if a packet is
received where the source IP address and the IP address or resolved hostname match, but the IP
address of endpoint identifier is not provisioned in the access device list for any of the groups, the
packet is discarded.
System administrators can use the command line interface to enable or disable this security
feature.