MDS 05-6628A01, Rev. B
MDS Orbit MCR-4G Technical Manual
65
User Management and Access Controls
Understanding
There are three user accounts/roles (admin, technician, and operator) for management access.
Users in the
admin
group have the highest privilege and can read everything in the tree that is
readable, write everything that is writable, and can execute any of the requests.
Users in the
tech
group have less access than admin. Generally, the tech group cannot configure any
security related configuration.
Users in the
oper
group can only view status and configuration. They do not have access to modify the
device configuration.
By default, the password for each account is the same as the username. The passwords should be
changed by users prior to deploying the device. When local user management is being used,
passwords are stored in non-volatile memory using PKCS#5 based encryption.
The user authentication can be done using locally stored passwords or via RADIUS.
Configuring
The password for each user account can be changed using a request:
admin@(none) 01:04:19> request system authentication change-password user admin password
new_password
User authentication order can be specified to give preference to which method is used first when
authenticating user access. In the following example, the list of RADIUS servers will be contacted first
before the local authentication rules are used.
NOTE:
If the local-users option is specified
before
RADIUS, then only the local-users option will be
utilized; the RADIUS servers will never be contacted.
admin@(none) 01:05:07% set system authentication user-authentication-order [ radius local-users ]
admin@(none) 01:05:07% commit
Monitoring
Ensure the CLI is in operational mode. Follow the example below to see the history of login attempts
by reviewing the event log:
admin@(none) 01:21:48> show logging event-log event-type console_login
logging event-log 62625
time-stamp 2011-12-21T01:18:08.00:00