Groups and users can also be authorized to manage power while connected to devices. The console server has two default
users (admin and root) and four pre-defined user groups: admin, appliance-admin, shell-login-profile and user.
A user account must be defined for each user on the console server or on an authentication server. The admin and root users
have accounts by default, and either administrator can add and configure other user accounts. Each local user account is
assigned to one or more of the user groups.
NOTE: When a user is removed from all groups, that user's privileges revert to those of the default user group. For
this reason, it is recommended custom groups be used and the default user group is not granted additional
privileges.
By default, all users have access to all ports on the console server. In order to authorize access via user groups, an
administrator must enable port access to be controlled by authorizations assigned to user groups.
NOTE: It is highly recommended you change the default passwords for root and admin before you put the console
server into operation.
To enable port access to be controlled by authorizations assigned to user groups:
1.
From the Expert tab of the side navigation bar, click
System - Security - Security Profile
.
2.
Under the Serial Devices heading, click Controlled by Access Rights assigned to User Groups and specific
users button, then click
Save
.
Local accounts
The console server has two local user accounts by factory default:
•
admin: Performs the initial network configuration. The factory default password for admin is avocent. The admin
user is a member of the admin group and can configure the console server and ports as well as user and group
authorizations.
•
root: Has the same administrative permissions as the admin user but also has unlimited privileges from the
shell. The factory default password for root is linux. The root user is a member of the admin and shell-login-
profile groups. When a root user logs in via the CONSOLE port, SSH or Telnet, the session is pre-defined by the
login profile to go directly to shell. The login profile can be customized so that it does not go directly to shell.
To view user appliance access rights:
1.
Click
Users - Local Accounts - User Names
. The list of usernames displays in the content area.
2.
Click a username under the User Name heading. The content area displays the user information for the selected
user.
NOTE: When any username is selected, both the content area and side navigation bar change. The side navigation bar
displays specific menu options for Members and Access Rights (which include Serial, Power and Appliance rights).
3.
From the side navigation bar, click
Access Rights - Serial
or
Access Rights - Power
to access the screens
displaying the fixed access rights and permissions for the selected user.
NOTE: The Serial and Power screens are read-only and cannot be changed.
4. From the side navigation bar, click
Access Rights - Appliance
. The Appliance Access Rights screen appears
and lists all access rights available to the user. Available appliance access rights are:
•
View Appliance Information
•
Disconnect Sessions
•
Reboot Appliance
•
Appliance Flash Upgrade and Reboot Appliance
Vertiv™ | Avocent® ACS800/8000 Advanced Console Server Installer/User Guide
52