
Communications protocol lockout overview
The communications protocol lockout security feature allows you to set the
number of invalid login attempts that each user can make using a particular
protocol and communications method before being locked out (a user is defined
as a user login and password combination).
For protocols that are not session-based (ION), you can configure how often the
device registers invalid login attempts by configuring the session timeout. You can
also configure the lockout duration for all configurable protocols.
Session timeout specifies the active duration for a protocol; during this time,
repeated invalid login attempts using the same USER/password combination are
not registered (repeated invalid attempts with different combinations are still
registered). Session timeout only applies to protocols which are not session-based
(ION) and send credentials with each packet, and should be configured to help
prevent accidental lockouts and filling the meter’s event log with protocol access
events
NOTE:
If protocol lockout is set to 0 (zero) there is no limit to the number of
invalid login attempts and the protocol will never be locked out. However, the
invalid login attempt events are recorded if the meter is configured to record
invalid access attempts.
User1
pw = 23
User1
pw = 23
User1
pw = 23
User1
pw = 23
T=0
T=10
T=32
T=65
0 0 1
0 0 1
0 0 2
0 0 3
Session Timeout = 30 minutes
= Lockout event
= Invalid login attempt
T
Lockout duration = 1440 minutes
= Time (minutes)
= Logged event
= Counter of invalid attempts
User1 valid password = 11
= Valid login attempt
User2 valid password = 22
0 0 1
User1
pw = 3
User1
pw = 4
User1
pw = 0
User2
pw = 22
T=0
T=10
T=22
T=45
0 0 1
User2
pw = 22
T=45
0 0 2
0 0 3
Scenario 1
User repeatedly enters the
same incorrect password to
attempt access to the meter
Scenario 2
User enters different
passwords to attempt access
to the meter
Lock attempts = 3
Once a user is locked out, the device will not accept login attempts from that user
on that protocol and communications method until the lockout duration has
passed. Invalid login attempts accumulate until the user has completed a valid
login or is locked out. If the user enters the correct USER/password combination
before being locked out, the invalid attempt counter is reset to zero. Even if the
user is locked out using ION over Ethernet, that user can still access the device by
entering the correct USER/password combination over a different protocol and
communications method.
116
7EN05-0390-00
Содержание 9810 Series
Страница 1: ...9810 series User manual 7EN05 0390 00 09 2018 www usa siemens com pds ...
Страница 4: ......
Страница 12: ......