12.7  

Security Features 
 

12.7.1  

Access Security 
 

12.7.1.1  

User-Specific Logon for WBM 
To ensure that authorized users have access to the HiPath 3000/5000 and to prevent unauthorized access, users must be identified by a user name and authorized by a password. This applies to all local and remote administration and maintenance procedures using Web-Based Management (WBM).
The user group determines which data is administered. The following two user groups are permanently defined for administration via WBM:
 •   Customer
 •   Administrator
Each user group is assigned a fixed user name and password. You need a valid user name and password to access a user group. Only the data authorized for the relevant user group can be read and administrated.
The following table provides a breakdown of the two user groups and their rights for each of the setup wizards.

 Table 12-9   WBM User Groups with Associated Rights
 Wizard  
 Customer  
 Administrator  
Initial Installation  
(for basic system setup)  
   
 X  
New Components:  
(for configuring new components)  
 •   LAN telephones (for configuring additional IP workpoints)
   
 X  
 •   WLAN telephones (for configuring additional WLAN workpoints)
   
 X  
 •   Analog telephones (for configuring additional analog workpoints - group 3 fax devices, for example)
   
 X  
 •   Not for U.S.: S0 interfaces (for configuring additional ISDN connections and ISDN workpoints)
   
 X  
 •   Licensing (for licensing system expansions)
   
 X  
Change Feature:
(for modifying current system setup data)  
 •   LAN/WLAN telephones (for modifying configured workpoints)
   
 X  
 •   Analog telephones (for modifying configured analog workpoints)
   
 X  
 •   Not for U.S.: S0 interfaces (for modifying configured ISDN connections and ISDN workpoints)
   
 X  
 •   For U.S. only: T1 board (for configuring and modifying the T1 board operating mode)
   
 X  
 •   Trunk seizure (for modifying the code and prioritization for trunk seizure)
   
 X  
 •   Answer machine (for configuring and modifying the integrated voice mailboxes)
   
 X  
 •   Call forwarding no answer/call pickup (for configuring and modifying call forwarding destinations and call pickup for incoming calls)
 X  
 X  
 •   Call groups (for configuring and modifying call groups (incoming calls are signaled to all members of a call group))
 X  
 X  
 •   Key programming (for configuring and modifying key programming on the workpoints)
 X  
 X  
 •   Internal phonebook (for configuring and modifying entries in the central phonebook)
 X  
 X  
 •   DHCP (for modifying to the DHCP server)
   
 X  
 •   Firewall (for configuring and modifying the integrated Internet firewall)
   
 X  
 •   DSL (for modifying Internet access)
   
 X  
 •   Internet telephony (for configuring and modifying Internet telephony access)
   
 X  
 •   VPN (for configuring and modifying virtual private networks)
   
 X  
 •   Online help (for configuring and modifying the installation directories in the online help)
   
 X  
Remote Access  
(for activating and deactivating remote access for remote system administration)  
   
 X  
Software Update  
(for checking if software updates are required)  
   
 X  
Status:
(for querying the current system status)  
 •   Network interfaces (for querying the current status of network interfaces)
 X  
 X  
 •   Dial-up networking (PSTN) (for querying information about existing dial-up connections (PSTN partners))
 X  
 X  
 •   Stations (for querying the data of all configured stations)
 X  
 X  
 •   Events (for querying the last 50 events (trace messages))
 X  
 X  
Expert Mode  
(for configuring and modifying advanced features, such as, the networking of several HiPath 3000/5000 systems)  
   
 X  

12.7.1.2  

Password Protection against Brute Force Attacks 
Brute force attacks are attempts made by a computer program to crack the password of another program or tool, by trying all possible combinations of letters and numbers.
To protect against unauthorized access, remote access logon to WBM is monitored. Users are permitted five attempts over five minutes to enter the correct password. If this time expires or the password is entered incorrectly five times, remote access is blocked.
The system's event log records the password input attempts.

12.7.1.3  

Logon With User Name and Password 

Security  
To ensure that authorized users have access to the HiPath 3000 and to prevent unauthorized access, users must be identified by a user name and authorized by a password. This applies to all local and remote administration and maintenance procedures using HiPath 3000/5000 Manager E, Assistant T, HiPath 3000/5000 Manager C, Manager TC, and AMHOST.
After the first system startup and during country initialization, you can select between the following security options:
 •   variable password (default)
 •   Fixed password
Example of first-time login with Assistant T

 Step  
 Input  
 Description  
 1.  
 *95  
Start system administration  
 2.  
 31994  
Default user name  
 3.  
 31994  
Default password  
    
Alphanumeric characters cannot be entered at all workpoints. Therefore, when changing the user name or password with Assistant T/Manager TC, you may enter additional characters as long as you never use an appropriate workpoint.  
Alphanumeric characters can only be entered at the following workpoints: OpenStage 40/60/80, optiPoint 600 office (in UP0/E mode), optiPoint 410 advance and optiPoint 420 advance.  
    
 Step  
 Input  
 Description  
 4.  
 XXXXX  
You are prompted to enter a new password (max. 15 digits).  
 5.  
 XXXXX  
You are prompted to confirm the password entered in step [4].  
 6.  
 29-5  
Country initialization  
 7.  
 X  
You are prompted to select the password type:  
1 = Variable password  
2 = Fixed password  
 8.  
 XX  
You are prompted to enter the country code (see Seite -26). The system then boots up with the country-specific default information.  
Notes:  
 •   On step [4] and step [5]: If a new password is issued, both steps are omitted when calling the system again.
 •   On step [6]: No country adjustment is necessary for Germany because the system starts up with German codes.
 •   On step [7]: When selecting the fixed password, the default password (31994) overwrites the new password entered under step [4].

Variable password concept  
Up to 16 users can be assigned their own user ID with individual name, password, and a user group consisting of six pre-determined user groups (in Table 12-10). Only the data authorized for the relevant user group can be read and administrated.
During initial login, the system requests the identity of the user and demands a new password (max. 15 characters from the optiPoint 500 character set). This then overwrites the default user name (31994) and default password (31994). This first user is then automatically assigned to the user group "System Maintenance". The system informs the user that no user is configured in the system and that the user has been assigned with "System Maintenance" authorization. Using HiPath 3000/5000 Manager E or Assistant T, additional users and their passwords can be configured in the user administration.
If a user forgets a password, it has to be deleted and re-configured by a different authorized user. If all authorized users forget their passwords, the system must be regenerated.

Fixed password concept  
When using a fixed password, only fixed user groups with unchangeable default user names and default passwords are used. Also, new users cannot be configured in the user administration.

Changing password types  
Only with Assistant T can you change from a variable password to a fixed password type and vice versa. To do this, you have to re-initialize the country settings. This switches the entire content of the customer database (including user names and passwords) to a default state.
If you perform country initialization in a system with a variable password, the previously created user names and passwords remain intact as long as you do not subsequently change the password type.
If a CDB is read from a system in which the default user names and passwords were changed, this CDB cannot be loaded into a HiPath 3000 system that was changed to a fixed password type. Before reading this CDB, you have to set up a user (user name and password) in the system that matches a user group with a fixed password. Once this user has been set up, the CDB can be read from the HiPath 3000. With this user name and ID, you can now load the CDB into the system switched to the fixed password type.

12.7.1.4  

Pre-Determined User Groups and Their Access Rights 

User groups with a variable password  
The following table shows the six pre-determined user groups and their access rights.

 Table 12-10   Variable password concept: Pre-Determined User Groups and Their Access Rights
 No.  
 User groups
   
User rights  
 User
admin.
 
 Audit  
 System maint.  
 (Service)  
 Customer admin.  
 (Cust.)  
 Charge  
 accounting  
 Develop-  
 ment  
 1.  
 •   Setting up/deleting users
 •   Assigning users to user groups
 X  
   
 X1  
   
   
   
 2.  
 •   Assessing and archiving backup-related log files
 •   Reader rights to system data (error memory, for example), not including confidential customer information
   
 X  
 X2  
   
   
   
 3.  
 •   Access rights to all system data (not including development access rights) as long as no users are assigned to other user groups.
   
   
 X  
   
   
   
 4.  
 •   Access rights to confidential customer information
 •   Executing customer actions (printing out certain lists, for example)
   
   
 X3  
 X  
   
   
 5.  
 •   Access rights to non-confidential customer information
   
   
 X  
 X  
   
   
 6.  
 •   Access rights to parameters and call detail recording actions (not including interface parameters for the output device)
   
   
 X3, 4  
 X4  
 X  
   
 7.  
 •   Access rights of the "System Maintenance" user group
 •   Setting up and reading certain parameters to which no other user group has access.
   
   
   
   
   
 X  
1As long as no user is assigned to the "User Administration" user group.
2As long as no user is assigned to the "Audit" user group.
3As long as no user is assigned to the "Customer administration" user group.
4As long as no user is assigned to the "Accounting" user group.

User groups with a fixed password  
The following table shows fixed (unchangeable) user groups and their rights.

 Table 12-11   Fixed Password: Fixed user groups and their access rights
 No.  
 User groups
   
   
   
   
   
User rights  
 System maint. (Service)  
 Name/Password=
31994/31994  
 Customer admin. (Cust.)  
 Name/Password:  
 - Manager TC=*95/(Password
not necessary)  
 - Manager C=office/office  
 Development  
 1.  
 •   Assessing and archiving backup-related log files
 •   Reader rights to system data (error memory, for example), not including confidential customer information
 X  
   
 X  
 2.  
 •   Access rights to all system data (not including development access rights)
 X  
   
 X  
 3.  
 •   Access rights to confidential customer information
 •   Executing customer actions (printing out certain lists, for example)
 X  
 X  
 X  
 4.  
 •   Access rights to non-confidential customer information
 X  
 X  
 X  
 5.  
 •   Access rights to parameters and call detail recording actions (not including interface parameters for the output device)
   
 X  
   
 6.  
 •   Setting up and reading certain parameters to which no other user group has access.
   
   
 X  

12.7.1.5  

System Access Options 
The user's access rights, meaning the data that the user may read or manage, always depend on the user group to which the user is assigned.

Service tools  
 •   Assistant T and Manager TC
Log on by entering your user name and password (regardless of code lock)
The system can only be accessed using the first two UP0/E connections from the first SLMO/SLU board in the system.
 •   HiPath 3000/5000 Manager E and HiPath 3000/5000 Manager C (local)
Log on by entering your user name and password.
 •   HiPath 3000/5000 Manager E (remote), direct connection
Log on by entering your user name and password.
The system can be accessed directly using the integrated digital modem (B channel) or the integrated analog modem. However, the user is required to establish a 5 digit access code beforehand.
 •   HiPath 3000/5000 Manager E (remote), callback connection
Log on by entering your user name and password.
The system can be accessed using the integrated digital modem (B channel) or the integrated analog modem. However, you have to set up a callback index beforehand.
 •   HiPath Software Manager
Log on by entering your user name and password.

AMHOST  
The AMHOST (Administration and Maintenance via HOST) feature allows Plus products to read certain system information and to change it, if necessary. To enable Plus products to access the system, you have to set up a user without a user group in the HiPath 3000 default user administration. Enter "AMHOST" as the user name and "77777" as the default user password.
You can only change this password if the system is configured using a variable password. In this case, delete the "AMHOST" user and re-configure the system with the same user name and a new password.

12.7.1.6  

Customer Data Security 
When saving a customer database on the hard disk, a user table (part of the user administration) with user name and encrypted passwords are also saved. This guarantees access security when the customer database is opened offline later on.
When opening the customer database offline, you are requested to enter your user name and password. The data that you enter is compared to the data in the user table. In this case, the user group verified during this process also determines the access rights.
When loading an offline customer database into HiPath 3000, the user table that goes with it should not be loaded into the system. Otherwise, the system-specific user administration would be distorted.
When you generate a default customer database offline, a default user table is also set up. If you generate a customer database like this, you can only load it into a default system.