
Security Using the VT100 Interface
You can connect the MAX 800 unit control port directly to a workstation running VT100-terminal-emulation software and use the VT100 configuration interface to restrict MAX 800 configuration access. If you use this method, you do not have to assign an IP address before restricting access. (After you have assigned an IP address, you can also use Telnet to establish a VT100 configuration session with the MAX 800. The Telnet session establishes a VT100 configuration environment that is identical to the VT100 configuration interface established through the control port.)
Accessing the VT100 interface
To access the VT100 interface, first connect a terminal or terminal emulator to the control port, as described in Setting up a controlling computer. Leave the terminal or emulator running, and start the MAX 800, as described in Starting the MAX 800.
When the MAX 800 completes its POST, press any key to display the Main Edit Menu and status windows
Restricting access automatically granted to all callers
To restrict the access automatically granted to all callers on a new MAX 800, you must:
Ascend, to a secure password.
write to a secure password.
00-000 System
> 00-100 Sys Config
00-200 Sys Diag
00-300 Security
00-000 System
00-100 Sys Config
00-200 Sys Diag
> 00-300 Security
00-300 Security
> 00-301 Default
00-302
00-303 Full Access
00-301 Default
> Name=Default
Passwd=
Operations=Yes
Edit Security=Yes
Edit System=Yes
Field Service=Yes
00-301 Default
Name=Default
Passwd=
> Operations=Yes
Edit Security=Yes
Edit System=Yes
Field Service=Yes
Exit?
> 0=ESC (Don't exit)
1=Exit and discard
2=Exit and accept
The top-level Security menu reappears:
00-300 Security
> 00-301 Default
00-302
00-303 Full Access
00-300 Security
00-301 Default
00-302
> 00-303 Full Access
00-303 Full Access
> Name=Full Access
Passwd=Ascend
Operations=Yes
Edit Security=Yes
Edit System=Yes
Field Service=Yes
Passwd=Ascend.
An edit field opens, delimited by brackets:
00-303 Full Access
Name=Full Access
Passwd:
[Ascend]
Edit System=YesA blinking text cursor appears in the brackets.
Field Service=Yes
Exit?
> 0=ESC (Don't exit)
1=Exit and discard
2=Exit and accept
The top-level Security menu appears:
00-300 SecurityLater, when you reset or power-cycle the MAX 800, the new, restrictive Default profile will be in effect. To configure the MAX 800, you will be required to supply the new password that you assigned in step 5 to activate the Full Access Security profile.
> 00-301 Default
00-302
00-303 Full Access
00-000 System
> 00-100 Sys Config
00-200 Sys Diag
00-300 Security
The Main menu appears.
00-000 System
10-000 PC CARD Modem
20-000 PC CARD Modem
30-000 Empty
40-000 PC CARD Modem
50-000 PC CARD Modem
60-000 PC CARD Modem
70-000 PC CARD Modem
80-000 PC CARD Modem
> 90-000 Ethernet
90-000 Ethernet
> 90-000 Ethernet
90-100 Connections
90-200 Names / Passwords
90-300 Bridge Adrs
90-400 Static Rtes
90-500 Filters
90-600 Firewalls
90-700 Answer
90-800 SNMP Traps
90-900 IPX Routes
90-A00 IPX SAP Filters
90-B00 Mod Config
90-000 Ethernet
90-000 Ethernet
90-100 Connections
90-200 Names / Passwords
90-300 Bridge Adrs
90-400 Static Rtes
90-500 Filters
90-600 Firewalls
90-700 Answer
90-800 SNMP Traps
90-900 IPX Routes
90-A00 IPX SAP Filters
> 90-B00 Mod Config
90-B00 Mod Config
> Ether options...
WAN options...
SNMP options...
Route Pref...
TServ options...
Bridging=Yes
IPX Routing=Yes
AppleTalk=Yes
Shared Prof=Yes
Telnet Security=Global
Telnet PW=xxxxx
RIP Policy=Split Horzn
RIP Summary=Yes
RIP Trigger=Yes
ICMP Redirects=Accept
DNS...
90-B00 Mod ConfigA blinking text cursor appears in the brackets.
Ether options...
WAN options...
SNMP options...
Route Pref...
TServ options...
Bridging=Yes
IPX Routing=Yes
AppleTalk=Yes
Shared Prof=Yes
Telnet Security=Global
> Telnet PW:
[]
ICMP Redirects=Accept
DNS...
Exit?
> 0=ESC (Don't exit)
1=Exit and discard
2=Exit and accept
The Ethernet menu reappears.
public by default, enabling SNMP managers to perform read commands. The read-write community string is write by default, enabling SNMP managers to perform read and write commands. You should change the read-write community string to a more secure password. To change the password:
90-B00 Mod Config
Ether options...
WAN options...
> SNMP options...
Route Pref...
TServ options...
Bridging=Yes
IPX Routing=Yes
AppleTalk=Yes
Shared Prof=Yes
Telnet Security=Global
Telnet PW=xxxxx
RIP Policy=Split Horzn
RIP Summary=Yes
RIP Trigger=Yes
ICMP Redirects=Accept
DNS...
90-000 Mod Config
SNMP options...
> READ Comm=public
R/W Comm Enable=Yes
R/W Comm=write
Security=No
RD Mgr1=0.0.0.0
RD Mgr2=0.0.0.0
RD Mgr3=0.0.0.0
RD Mgr4=0.0.0.0
RD Mgr5=0.0.0.0
WR Mgr1=0.0.0.0
WR Mgr2=0.0.0.0
WR Mgr3=0.0.0.0
WR Mgr4=0.0.0.0
WR Mgr5=0.0.0.0
Queue Depth=0
write.
An edit field opens, delimited by brackets:
SNMP options...
READ Comm=public
R/W Comm Enable=Yes
R/W Comm=
[]
A blinking text cursor appears in the brackets.
Exit?
> 0=ESC (Don't exit)
1=Exit and discard
2=Exit and accept
The Ethernet menu reappears.
The context-sensitive DO command menu appears:
DO...
> 0=Esc
P=Password
C=Close TELNET
Copyright © 1998, Ascend Communications, Inc. All rights reserved.