2 setting login security, 1 setting the password of router administrator, 2 creation of new login user – Hitachi GR2000 Series User Manual

Page 81: 2 setting login security -3, 1 setting the password of router administrator -3, 2 creation of new login user -3

Advertising
background image

Operation during initial installation

GR2K-GA-0015

4-3

Ver. 07-02

4.2

Setting login security

4.2.1

Setting the password of router administrator

To execute a configuration definition command, it is necessary that the user becomes
a router administrator using an enable command. When an enable command is
executed during initial installation, the user can become a router administrator
without being authenticated because the password of the router administrator has
not been set. However, it is dangerous in terms of security that all end users are able
to become a router administrator without being authenticated using a password
during normal operation. Set the password therefore of a router administrator in
advance during initial installation. An example of a password setting is shown in the
figure below.

Figure 4-3 Password setting of router administrator immediately after initial

installation

4.2.2

Creation of New Login User

The adduser command creates a new login user. An example of creating a login user
is shown in the figure below.

Figure 4-4 Creating a new login user

It is also recommended to register the user, registered in the RADIUS server, in the
router when RADIUS authentication is performed. However, the user can log in even
when he is registered in only the RADIUS server.

4.2.3

Deleting the login user during initial installation

Create a new login user and then delete the set login user using an rmuser command
to prevent deterioration of security when login user "operator" set during initial
installation is not used as a login user during operation.

command:cli

> enable

# password

Changing local password for admin.

New password:

New password:

>

> enable

# adduser

Login name: newuser

Password: *******

Retype new password: *******

Add user ‘newuser’: (y/n): y

# quit

>

Enter a login user name.

Enter a password (the entered characters are
not displayed).

Enter the password again to confirm (the
entered characters are not displayed).

Select whether you want to create a user.
"y": Create a user.
"n": Do not create a user.

Advertising