Nortel Networks 42C4911 Switch User Manual


 
Alteon OS Application Guide
Chapter 1: Accessing the Switch
6142C4911, January 2007
An SCP-only administrator’s password is typically used when SecurID is used. For exam-
ple, it can be used in an automation program (in which the tokens of SecurID are not avail-
able) to back up (download) the switch configurations each day.
NOTEThe SCP-only administrator’s password must be different from the regular administra-
tor’s password. If the two passwords are the same, the administrator using that password will
not be allowed to log in as an SSH user because the switch will recognize him as the SCP-only
administrator. The switch will only allow the administrator access to SCP commands.
End User Access Control
Alteon OS allows an administrator to define end user accounts that permit end users to perform
operation tasks via the switch CLI commands. Once end user accounts are configured and
enabled, the switch requires username/password authentication.
For example, an administrator can assign a user, who can then log into the switch and perform
operational commands (effective only until the next switch reboot).
Considerations for Configuring End User Accounts
A maximum of 10 user IDs are supported on the switch.
Alteon OS supports end user support for Console, Telnet, BBI, and SSHv1/v2 access to
the switch. As a result, only very limited access will be granted to the Primary Administra-
tor under the BBI/SSH1 mode of access.
If RADIUS authentication is used, the user password on the Radius server will override
the user password on the GbE Switch Module. Also note that the password change com-
mand on the switch only modifies the use switch password and has no effect on the user
password on the Radius server. Radius authentication and user password cannot be used
concurrently to access the switch.
Passwords can be up to 15 characters in length for TACACS, RADIUS, Telnet, SSH, Con-
sole, and Web access.