Security parameters

The following table shows the provisionable security parameters.

Table A-8: Security parameters

Parameter

TL1 Commands (Access) (Note)

Range

Default

Related WaveStar® CIT Commands

Password (pid)

ENT-USER-SECU

ED-USER-SECU

(P, A)

At least one alphabetic and at least three non-alphabetic characters. Of the three nonalphabetic characters, at least one must be a numeric character and at least one must be a symbolic character. The third non-alphabetic character can be either a numeric or a symbolic character.

Administration → Security → Provision User Logins

User Access Privilege (uap)

PRIVILEGED ADMINISTRATION GENERAL MAINTENANCE REPORTS-ONLY

Password Aging Interval (page)

0 (disabled), 7-999 days

0

Inactivity Timeout Period (tmout)

0-999 minutes

30 minutes

Allow Login (alw_login)

Enabled, Disabled

Enabled

Administration → Security → Provision User Logins

Administration → Security → Enable User Login

Administration → Security → Disable User Login

New User ID (new_uid)

ED-USER-SECU

(P, A)

alphanumeric string of 5-10 characters

(none)

Administration → Security → Provision User Logins

New Password (new_pid)

At least one alphabetic and at least three non-alphabetic characters. Of the three nonalphabetic characters, at least one must be a numeric character and at least one must be a symbolic character. The third non-alphabetic character can be either a numeric or a symbolic character.

Lockout Status (lockout_status)

Enable Login

Old Private Identifier/ password (old_pid)

ED-PID

(P, A, G, M, R)

At least one alphabetic and at least three non-alphabetic characters. Of the three nonalphabetic characters, at least one must be a numeric character and at least one must be a symbolic character. The third non-alphabetic character can be either a numeric or a symbolic character.

(none)

Administration → Change Password

New Private Identifier/ password (new_pid)

Security State (state)

ENT-CID-SECU

(P)

IS (no lockout),

LO (Lockout)

IS

Administration → Security → Enable Lockout Security State

Administration → Security → Disable Lockout Security State

User ID Aging Period (usrage)

ED-NE-SECU

(P, A)

0 - 999 Days

60

Administration → Security → Provision NE Security

Failed Login Attempts Lockout Period (intrvl)

0 - 99 Minutes

10

Failed Login Attempts Lockout Threshold (thrshld)

2 - 99

5

Failed Login Attempts Lockout Aging Period (age)

1 - 999 Minutes

60

Minimum Waiting Period before Changing Password (pidwpd)

0 - 30 Days

20

Change Password Status (chg_pwd_stat)

Enable, Disable

Disable

Community Identifier for SNMP user (ucomid)

ENT-SNMP-USER

(P)

case-sensitive alphanumeric string of 6 to 15 characters

None

Administration → Security → Provision SNMP Users

User IP address (uipadr)

32-bit IP address

None

Request Functionality (reqfnct)

Enabled, Disabled

Enabled

Trap Functionality (trapfncts)

Enabled, Disabled

Enabled

RADIUS Server IP Address (ipaddr)

ENT-RADIUS-USER

(P)

Four dot-separated decimal numbers ranging from 0 to 255. The value 0.0.0.0 is invalid

None

Administration → Security → Provision RADIUS Server

UDP port number for RADIUS. (port)

1 to 65535

1812

Role of RADIUS Server (role)

Primary, Secondary

Secret

At least one alphabetic and at least three non-alphabetic characters. Of the three nonalphabetic characters, at least one must be a numeric character and at least one must be a symbolic character. The third non-alphabetic character can be either a numeric or a symbolic character.

Note: The TL1 command security access levels are Privileged (P), Administration (A), General (G), Maintenance (M), and Reports-only (R).

Copyright © 2011 Alcatel-Lucent. All rights reserved.