19-55
Cisco ONS 15454 Procedure Guide, R5.0
September 2005
Chapter 19 DLPs A200 to A299
DLP-A272 Change Security Policy on Multiple Nodes
DLP-A272 Change Security Policy on Multiple Nodes
Step 1
From the View menu, choose
Go to Network View
.
Step 2
Click the
Provisioning
>
Security > Policy
tabs. A read-only table of nodes and their policies appears.
Step 3
Click a node on the table that you want to modify, then click
Change
.
Step 4
If you want to modify the idle user timeout period, click the hour (H) and minute (M) arrows in the
Idle User Timeout area for the security level you want to provision: RETRIEVE, MAINTENANCE,
PROVISIONING, or SUPERUSER. The idle period time range is between 0 and 16 hours, and 0 and 59
minutes. The user is logged out after the idle user timeout period is reached.
Step 5
In the User Lockout area, you can modify the following:
•
Failed Logins Before Lockout—The number of failed login attempts a user can make before the user
is locked out of the node. You can choose a value between 0 and 10.
•
Manual Unlock by Superuser—Allows a user with Superuser privileges to manually unlock a user
who has been locked out of a node.
•
Lockout Duration—Sets the amount of time the user will be locked out after a failed login. You can
choose a value between 0 and 10 minutes in five-second intervals.
Step 6
In the Password Change area, you can modify the following:
•
Prevent Reusing Last [ ] Passwords—Choose a value between 1 and 10 to set the number of different
passwords the user must create before they can reuse a password.
•
Cannot Change New Password for [ ] days—If checked, prevents users from changing their
password for the specified period. The range is 20 to 95 days.
•
Require Password Change on First Login to New Account—If checked, requires users to change
their password the first time they log into their account.
Step 7
To require users to change their password at periodic intervals, check the
Enforce Password Aging
check box in the Password Aging area. If checked, provision the following parameters:
•
Aging Period—Sets the amount of time that must pass before the user must change his or her
password for each security level: RETRIEVE, MAINTENANCE, PROVISIONING, and
SUPERUSER. The range is 20 to 95 days.
•
Warning—Sets the number days the user will be warned to change their password for each security
level. The range is 2 to 20 days.
Step 8
In the Other area, you can provision the following:
•
Single Session Per User
—
If checked, limits users to one login session at one time.
•
Disable Inactive User—If checked, disables users who do not log into the node for the period of time
specified in the Inactive Duration box. The Inactive Duration range is 45 to 90 days.
Purpose
This task changes the security policy for multiple nodes including idle user
timeouts, user lockouts, password change, and concurrent login policies.
Tools/Equipment
None
Prerequisite Procedures
DLP-A60 Log into CTC, page 17-66
Required/As Needed
As needed
Onsite/Remote
Onsite or remote
Security Level
Superuser
Summary of Contents for ONS 15454 Series
Page 28: ...Tables xxviii Cisco ONS 15454 Procedure Guide R5 0 December 2004 ...
Page 44: ...Tasks xliv Cisco ONS 15454 Procedure Guide R5 0 December 2004 ...
Page 53: ...liii Cisco ONS 15454 Procedure Guide R5 0 December 2004 About this Guide Document Conventions ...
Page 55: ...lv Cisco ONS 15454 Procedure Guide R5 0 December 2004 About this Guide Document Conventions ...
Page 850: ...Index IN 22 Cisco ONS 15454 Procedure Guide R5 0 December 2004 description 4 11 remove 18 23 ...