
System Administration
22
Table 4.1. User login levels
Level
Description
NOBODY
No access to any menu items, but can access control
switches for which the user has access.
GUEST
Guest user, access to some menu items
USER
Normal unprivileged user
ADMIN
System administrator
DEBUG
System debugging user
Tip
In general you only want to use NOBODY, ADMIN or DEBUG levels.
4.1.2. Configuration access level
The configuration access level determines whether a user has read-only or read-write access to the
configuration, as shown in Table 4.2 below. This mechanism can also be used to deny all access to the
configuration using the
none
level, but still allowing access to other menus and diagnostics.
This setting is distinct from, and not connected with, the login level described above. You can use the access
level to define, for example, whether a USER login-level user can modify the configuration. Typically an
ADMIN (or DEBUG) login-level user would always be granted full access, so for ADMIN or DEBUG level
user's, the default of
full
is suitable.
Table 4.2. Configuration access levels
Level
Description
none
No access unless explicitly listed
view
View only access (no passwords or hashes)
read
Read only access (with passwords and hashes)
full
Full view and edit access - DEFAULT
4.1.3. Login idle timeout
To improve security, login sessions to either the web user interface, or to the command-line interface (via telnet,
see Chapter 16), will time-out after a period of inactivity. This idle time-out defaults to 5 minutes, and can be
changed by setting the
timeout
attribute value.
The time-out value is specified using the syntax for the XML fb:duration data type. The syntax is hours, minutes
and seconds, or minutes and seconds or just seconds. E.g.
5:00
.
To set a user's time-out in the user interface, tick the checkbox next to
timeout
, and enter a value in the
format described above.
Setting a timeout to 0 means unlimited and shoudl obviously be used with care.
4.1.4. Restricting user logins
4.1.4.1. Restrict by IP address
You can restrict logins by a given user to be allowed only from specific IP addresses, using the
allow
attribute.
This restriction is per-user, and is distinct from, and applies in addition to, any restrictions specified on either the
web or telnet (for command line interface access) services (see Section 12.3 and Section 12.4), or any firewall
rules that affect web or telnet access to the FB6000 itself.
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......