Configuring the Shelf Controller
Restricting administrative access
APX 1000™ Getting Started Guide
5-5
After you have supplied basic IP information, as described in “Providing a basic system IP
configuration” on page 5-7, you can access the APX 1000 command-line interface by using
Telnet from an IP host. This type of connection requires that you authenticate a User profile
and supply a password to acquire administrative permissions. During basic configuration,
Lucent Technologies recommends that you also configure the serial port to require username
and password authentication. For more information, see “Restricting administrative access” on
page 5-5.
For details about User profiles, see the APX 8000/MAX TNT Administration Guide.
Restricting administrative access
Each APX 1000 unit is shipped from the factory with its security features set to defaults that
allow you to easily access the unit so you can configure it without any restrictions. Before you
bring the unit online, you must change the default security settings to protect the configured
unit from unauthorized access.
Changing defaults for serial-port logins
The factory default setting for the shelf controller serial interface specifies that any connection
to that interface will use the
admin
User profile. To help protect the system from
unauthorized administrative access on the serial interface, change the following default setting:
[in SERIAL/
{ { shelf-1 controller 1 } 0 }
]
user-profile = admin
An APX 1000 unit automatically creates a Serial profile for the shelf controller. To list the
Serial profiles, use the Dir command as follows:
admin> dir serial
To make the serial login more secure, modify the Serial profile to specify a null User profile
name, as shown in the following example. Anyone trying to establish a connection through the
serial port is then required to provide the username
admin
, or another valid username, and the
correct password.
admin> set user-profile =
admin> write
Changing the default
admin
password
Because the
admin
User profile controls permissions that enable most levels of activity,
access to that login must be carefully restricted. To protect the
admin
login, change its
Parameter
Setting
User-Profile
Name of the User profile to be used for logins on the shelf
controller serial port. User profiles set permissions and other
parameters for logins to the APX 1000 command-line interface. If
no name is specified, the system prompts for both the name and
password of a User profile, as it does for Telnet logins.