Service Logins With Asg Authentication - Avaya G430 Manual

Administering branch gateway
Hide thumbs Also See for G430:
Table of Contents

Advertisement

show login
authentication
show username
username

Service logins with ASG authentication

The gateway supports ASG authentication for remote service logins. Direct remote connection
of services to the gateway is needed for gateways that are under service contract, do not have
LSPs, and are controlled by external MGCs. ASG is a more secure authentication method than
password authentication and does not require a static password.
ASG uses one-time tokens for authentication, in which a unique secret key is associated with
each login. ASG authentication is a challenge-response system, in which the remote user
receives a challenge from the gateway and returns an ASG authenticated response that the
gateway verifies before permitting access. A new challenge is used for each access attempt.
ASG authentication is supported for remote services connecting to the gateway using Telnet
or SSH protocols via any of the following:
• Dial-up modem connected to the USB or Services port
• Frame relay or leased line
• Secure gateway VPN
• Direct connection to the front panel Services port using the "craft" login
When ASG authentication is enabled on the Gateway, the Gateway recognizes any login
attempts using Avaya Services reserved usernames as service logins, and requests ASG
authentication from the user, instead of a static user password.
The following usernames are reserved for Avaya Services usage: rasaccess, sroot, init,
inads, and craft.
When ASG authentication is enabled on the Gateway, all password user accounts with
usernames similar to the reserved service logins are deactivated.
Related topics:
Enabling ASG authentication
Replacing the ASG authentication file
Examples of configuring ASG authentication
Administering Avaya G430 Branch Gateway
Command
on page 40
Description
View the login authentication settings and information
This includes information on the configured lockout
period, inactivity period, expiration period, password
length, and characters that must be included in the
password.
Display information about the local user accounts
Add or remove a local user account
on page 40
on page 41
Security overview
October 2013
39

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents