Terminal (Program Port/Telnet) Commands
124
NX-Series Controllers - WebConsole & Programming Guide
3.
To proceed, enter
y
and press
enter
. The following menu displays:
Select to change current security option
1) Audit Log.................................. Disabled
2) Banner Disply.............................. Disabled
3) Inactivity Timeout......................... Disabled
4) Failed Login Lockout....................... Disabled
5) OCSP....................................... Disabled
6) Password Expiration........................ Disabled
7) Usb........................................ Enabled
8) Auth on server port (telnet, ftp).......... Enabled
9) Auth on ICSP Lan .......................... Disabled
10) Encryption on ICSP Lan .................... Disabled
11) Auth on ICSP-ICSLan ....................... Disabled
12) Encryption on ICSP-ICSLan ................. Disabled
13) HTTP Service............................... Enabled
14) HTTPS Service.............................. Enabled
15) Telnet Service............................. Enabled
16) SSH Service................................ Enabled
17) FTP Service................................ Enabled
18) SFTP Service............................... Enabled
19) ICSP on WAN................................ Enabled
20) ICSP on ICSLan............................. Enabled
21) General Configuration Security............. Disabled
22) LDAP Security.............................. Enabled
Or <ENTER> to return to previous menu
4.
To enable LDAP Security, enter
21
and press
Enter
. The same menu will be sent to the screen with LDAP Security set to
Enabled. Press enter to return to the Security Setup menu.
5.
When back to the Security Setup menu, enter
17
and press
Enter
.
A prompt to enter the LDAP URI will be displayed. Once you enter the URI is entered and press enter, a prompt for the next
LDAP parameter appears.
Continue entering the LDAP server parameters until all parameters are entered. The Security Setup menu displays again.
6.
To test the connection to the server enter
18
and press
Enter
.
This test performs a bind to the BIND DN using the Search Password entered. If the bind is successful, "
Connection
successful
" appears on the screen. If the server could not be reached or the bind is unsuccessful, "
Could not connect to
server
" appears on the screen.
7.
Press
Enter
to return to the main menu.
NOTE:
Options 3 - 14 (Add user, Edit user, Delete user, Show the list of authorized users, Add device, Edit device, Delete device, Show
list of authorized devices, Add role, Edit role, Delete role, Show list of authorized roles) on the Security Setup menu are disabled when
LDAP is enabled.
Security Options Menu
Select "
Set system security options for NetLinx Master
" (option
1
) from the Setup Security Menu to access the
Security Options
menu, described in the following table:
Security Options Menu
Command
Description
1) Audit Log
This selection enables/disables remote syslog.
2) Banner Display
This selection enables/disables banner messages.
3) Inactivity Timeout
This selection enables/disables whether the Master logs out a user after a defined period of
inactivity.
4) Failed Login Lockout
This selection enables/disables whether the Master places a lock on a user account after a set
number of failed logins.
5) OCSP
This selection enables/disables usage of the Online Certificate Status Protocol (OCSP) to validate
received certificates before trusting the sending site.
6) Password Expiration
This selection enables/disables whether the Master forces a user to change its password after a set
period of time.
7) USB
This selection enables/disables all Type-A USB connectors on the Master.
8) Auth on server port
(Telnet, FTP)
This selection enables/disables whether the Master requires user name and password
authentication on Telnet, Program, and HTTP/HTTPS ports.
9) Auth on ICSP LAN
This selection enables/disables whether the Master requires user name and password
authentication on devices connected to the LAN ports on the Master.
10) Encryption on ICSP LAN
This selection enables/disables whether there is encryption on the LAN ports on the Master.