Security Management - Ericsson MINI-LINK 6351 Technical Description

Hide thumbs Also See for MINI-LINK 6351:
Table of Contents

Advertisement

For more information about license management, see License System.
7.9

Security Management

All management access to the NE is protected by a user name and a password.
The following user roles are defined:
Note: Only the sys-admin has full read and write access. The operator and
All users have an associated password. All users can change their own
passwords, but only users with the sys-admin user role can change passwords
for other users.
Secure Shell (SSH) protocol can be used for secure remote access and use of
CLI commands.
The packet radio offers two types of authentication towards the external SSH
server: passwords or the Rivest-Shamir-Adleman (RSA) key algorithm. The
RSA algorithm uses a public and a private key for authentication and makes
it possible to log on without a password. The key pair is generated on the
SSH server with a maximum size of 1024 bits. The public key is placed on the
SSH server, while the private key is installed on the packet radio. After the
installation of the private key, the NE is able to log on to the external SSH
server without a password. Another advantage of using RSA keys is that it
provides protection for the external SSH server against brute-force attacks, as
the keys used are too long to crack them.
AAA
Authentication, Authorization, and Accounting (AAA) is a security architecture
for distributed systems. The Authentication process makes sure that only
accepted users can log on to the system, for example, using user names
and passwords. The Authorization process gives authenticated users certain
permissions, for example, based user roles. The Accounting process records
information about access and use of the system.
There are three AAA policies in MINI-LINK: local, RADIUS, and TACACS+.
Note: If the connection to the remote AAA server is interrupted, the NE falls
1/22102-HRA 901 17/9 Uen PU1 | 2016-07-04
guest with read-only access
operator with read and write access
net-admin with read and write access
sys-admin with read and write access
net-admin have full read access, but limited write access.
back to local authentication.
Management
45

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents