Avaya Nortel Communication Server 1000 Manual page 330

Ip line fundamentals
Hide thumbs Also See for Nortel Communication Server 1000:
Table of Contents

Advertisement

330 IP Line administration
Password guessing protection
Password guessing protection helps to block a hacker from attempting to log
into the Voice Gateway Media Card shell by making repeated attempts to
guess the shell user ID and password.
The password guessing protection is applicable to either a tip session (direct
maintenance port-connected TTY session) or a Telnet session.
The password guessing protection feature is described as follows:
Copyright © 2003–2008, Nortel Networks
.
SysContact: designer
OS Time: Date (04/03/2005) Time (09:07:43)
Use "logout" to logout.
Idle session timeout = 20 minutes.
IPL>
There is a logon failure threshold of 3 and a lockout period of 10 minutes.
This is not user-configurable.
Password guessing protection is enabled by default when the card starts
the first time. The protection can be disabled and re-enabled at the
VxWorks shell. Entering the shelllogonProtectSet 0 command
disables the protection and shelllogonProtectSet 1 enables it.
When the logon failure threshold is exceeded (by 3 consecutive failed
logon attempts), the system raises an "ITG1038" critical alarm. This
alarm is sent to indicate the card logon has been locked due to too many
incorrect password entries.
Alarm value = ITG alarm 38
perceivedSeverity = Critical
probableCause = Unauthorized maximum access attempts
Alarm text = IPL logon protection (logon locked)
When the 10 minute timer expires for the lockout period, the system
raises an "ITG5038" cleared alarm. The clear message is sent after
the lockout period expires.
perceivedSeverity = Cleared
probableCause = Unauthorized maximum access attempts
Alarm text = IPL logon protection (logon available)
There is no online indication or warning during the failed logon attempt
lockout state. Everything appears the same to the user trying to logon.
The user is not informed that logon blocking has been activated. The
logon is ignored for 10 minutes.
Both the critical and cleared alarms are sent as SNMP traps to the
system administrator. For security reasons, these two alarms do not call
the syslog function as the other itgAlarms do, so no syslog message is
displayed on the console or written in the syslog file.
Nortel Communication Server 1000
IP Line Fundamentals
NN43100-500 02.02 Standard
Release 5.5 4 February 2008

Advertisement

Table of Contents
loading

Table of Contents