Communications Protocol Lockout Overview - Siemens 9410 Series User Manual

Hide thumbs Also See for 9410 Series:
Table of Contents

Advertisement

9410 series

Communications protocol lockout overview

46
Set user passwords.
The communications protocol lockout security feature allows you to set the number of
invalid login attempts that each user can make using a particular protocol and
communications method before being locked out (a user is defined as a user login and
password combination).
For protocols that are not session-based (ION), you can configure how often the
device registers invalid login attempts by configuring the session timeout. You can also
configure the lockout duration for all configurable protocols.
Session timeout specifies the active duration for a protocol; during this time, repeated
invalid login attempts using the same USER/password combination are not registered
(repeated invalid attempts with different combinations are still registered). Session
timeout only applies to protocols which are not session-based (ION) and send
credentials with each packet, and should be configured to help prevent accidental
lockouts and filling the meter's event log with protocol access events
NOTE: If protocol lockout is set to 0 (zero) there is no limit to the number of invalid
login attempts and the protocol will never be locked out. However, the invalid login
attempt events are recorded if the meter access events are configured to record
invalid access attempts.
= Logged ev ent
= Loc kout e ve nt
Us e r1 va lid pa s s word = 11
= Invalid login attempt
Us e r2 va lid pa s s word = 22
= Valid login attempt
T
Loc
= Time (minute s )
Scenario 1
User repeatedly enters the
same incorrect password to
attempt access to the meter
Scenario 2
User enters dif ferent
passwords to attempt access
to the meter
Once a user is locked out, the device will not accept login attempts from that user on
that protocol and communications method until the lockout duration has passed.
Invalid login attempts accumulate until the user has completed a valid login or is locked
out. If the user enters the correct USER/password combination before being locked
out, the invalid attempt counter is reset to zero. Even if the user is locked out using
ION over Ethernet, that user can still access the device by entering the correct USER/
password combination over a different protocol and communications method (for
example, connecting to the device's RS-485 serial port using Modbus protocol).
0
0 1
= Counter of inv alid attempts
kout dura tion = 1440 minute s
T=0
T=10
0
0 1
0
0 1
User 1
Us e r1
pw = 23
pw = 23
T=0
T=10
0
0 2
0
0 1
User 1
Us e r1
pw = 0
pw = 3
T=32
T=45
0
0 2
Us e r2
Us e r1
pw = 22
pw = 23
T=22
T=45
0 3
0
Us e r1
Us e r2
pw = 4
pw = 22
7EN05-0336-03
Security
T=65
0
0 3
Us e r1
pw = 23

Advertisement

Table of Contents
loading

This manual is also suitable for:

94pmrdhwk

Table of Contents