
Chapter 3: System planning
Security planning
Page 3-38
Identify the user names and security roles of initial SNMPv3 users. Two security roles are
available:
Read Only
System Administrator
Identify the security level for each of the security roles. Three security levels are available:
(a) No authentication, no privacy
(b) Authentication, no privacy
(c) Authentication, privacy
If authentication is required, identify the protocol. The authentication protocol available is MD5.
If privacy will be used, identify the protocol. The privacy protocol available is cbc-des.
Managing module access by passwords
From the factory, each module has a preconfigured administrator-level account in the name
root
,
which initially requires no associated password. When you upgrade a module:
An account is created in the name
admin
.
Both
admin
and
root
inherit the password that was previously used to access the module, if:
o
Full Access password, if one was set.
o
Display-Only Access password, if one was set and no Full Access password was set.
Caution
If you use Wireless Manager, do not delete the root account from any module. If you
use a NMS that communicates with modules through SNMP, do not delete the root
account from any module unless you first can confirm that the NMS does not rely on
the root account for access to the modules.
Each module supports four or fewer user accounts, regardless of account levels. The available
levels are
ADMINISTRATOR, who has full read and write permissions. This is the level of the
root
and
admin
users, as well as any other administrator accounts that one of them creates.
INSTALLER, who has permissions identical to those of ADMINISTRATOR except that the
installer cannot add or delete users or change the password of any other user.
TECHNICIAN, who has permissions to modify basic radio parameters and view informational
web pages.
GUEST, who has no write permissions and only a limited view of General Status tab.
Admin, Installer and Tech accounts can be configured as READ-ONLY. This will allow the
account to only see the items.
The ability to view information of General Status tab can be controlled by the "Site Information
Viewable to Guest Users" under the SNMP tab.