
3-10
MAX Administration Guide
Terminal-Server Administrative Tasks
Using Show commands
incorrect tries, the MAX terminates the call. (ACE authentication is also known as SecurID
authentication.)
Enigma Logic SafeWord servers use SafeWord authentication, a form of token-card
authentication in which RADIUS forwards a connection request to an Enigma Logic SafeWord
server. The server sends an Access-Challenge packet back through the RADIUS server and the
MAX unit to the user dialing in. The user sees the challenge message, obtains the current
password from his or her token card, and enters the current password (also called a token). The
token travels back through the MAX unit and the RADIUS server to the SafeWord server. The
SafeWord server sends a response to the RADIUS server, specifying whether the user has
entered the proper user name and token. If the user enters an incorrect token, the SafeWord
server returns another challenge, and the user can again attempt to enter the correct token. The
server sends up to three challenges. After three incorrect entries, the MAX unit terminates the
call.
When the terminal-server is in password mode, it passively waits for password challenges
from a remote Security Dynamics ACE/Server or Enigma Logic SafeWord server. The Set
Password command applies only when the MAX unit uses security card authentication. Enter
the command as follows:
ascend% set password
Entering Password Mode...
[^C to exit] Password Mode>
Press Ctrl-C to return to normal terminal-server command-line interface operations and disable
Password Mode.
Each channel of a connection to a secure site requires a separate password challenge, so for
multichannel connections to a secure site, you must leave the terminal-server command-line
interface in password mode until all channels have been established.
The Ascend Password Protocol (APP) Server utility provides an alternative way to allow users
to respond to dynamic password challenges obtained from hand-held security cards. The APP
Server utility also enables a user to respond to password challenges received from an external
authentication server, such as an ACE/Server or SafeWord server. To allow a user to supply a
password from a host on the local network, you must configure the MAX unit to communicate
with the APP Server utility on that host.
Using Show commands
Use Show commands to see uptime and revision information, modem and V.110 card status,
Dialed Number Information Service (DNIS) activity, and information about filters.
Displaying uptime and revision
To see how long the MAX unit has been running, enter the Show Uptime command. For
example:
ascend% show uptime
system uptime: up 2 days, 4 hours, 38 minutes, 43 seconds