Benutzeranleitung / Produktwartung OL-5742-01 des Produzenten Cisco Systems
Zur Seite of 42
CH A P T E R 18-1 Cisco Signaling Gateway Manager User Guide OL-5742-01 18 Configuring SGM Security This chapter provides the follo wing info rmation about configuring SGM security and limiting access.
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-2 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 • Manually Disabling U sers and Passwords (Solaris On ly), page 18-.
18-3 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access Step 3 If you ha ve already conf igured the type of SGM security authent ication you want to use, skip to Step 4 .
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-4 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 T o enable Solaris auth entication, enter the follo wing command: # ./sgm authtype solaris See the “SGM Command Reference” section on page C-1 for more information on the use of e ach of the above SGM commands.
18-5 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access Note If sgm authtype is set to solaris , users cannot ch ange their passwords using the SGM client .
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-6 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 • The password cannot be a common w ord. SGM uses the dictionary located at /usr/lib/shar e/dict/wor ds to determine whether a word is common.
18-7 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access Note Access to SGM information and downlo ads on Cisco.com is al ready p rotecte d by Cisco.com, and is not protected by SGM.
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-8 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 • System Data Files – Notes – Vi e w s – Preferences • V iewing SG M documentation • Down loading client software Power User (Level 2) Access Po w er Users hav e acc ess to all Basic User functions.
18-9 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access • T elnet ting to the I TP • V iewing rout e table files and GTT f .
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-10 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 System Administ rators hav e access to the follo wing SGM W eb displ.
18-11 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access Step 2 Enter the follo wing command: # cd /opt/CSCOsgm/bin Step 3 (Optiona l) Y ou can configure SGM to gene rate an alarm after a specified number of unsuccessful login attempt s by a user .
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-12 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Step 5 (Optional) SGM keeps track of the date and time eac h user last logged in. Y ou can configure SGM to disable a user’ s secur ity authentication automaticall y after a specified n umber of days of inactivity .
18-13 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access If you ha ve enabled this function and you w a nt to disable it (that is, pre vent SGM from forcing users to change passw ords), enter the follo wing command: # .
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-14 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Manually Disabling Users and Passwords (Solaris Only) As described i.
18-15 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access Y ou ca n also re-enable the user’ s authenti cation with the same password, or with a ne w password: • T o re-enable the user’ s authentication with the same password as before, use the sgm enableuser command.
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-16 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Enabling and Changing Users and Passwords (Solaris Only) Of course, SGM also enables you to r e-enable users and passwords, and change user accounts.
18-17 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access Note If sgm authtype is set to solaris , you cannot use the sgm userpass command. Instead, you must manag e passwords on the e xternal authentication servers.
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-18 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Step 6 (Optional) T o ch ange a user’ s authenticati on lev el, but not the user’ s password, enter the following command: #.
18-19 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access • SGM displays the Message o f the Day dial og ( Figure 18-1 ).
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-20 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 If you want t o configure SGM to display a messag e of the day , you must first enable the function.
18-21 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access T o display the co ntents of the message of the day f ile, enter the followin g command: #.
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-22 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 SGM displays the follo wing in formation for each user: • User nam.
18-23 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access • Access to all privileged f iles and proc esses • Operating syste.
Chapter 18 Configuring SGM Security Configuring SGM User-B ased Access 18-24 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Disabling SGM User-Bases Access For so me reason, you might want to comp letely disable SGM User-Based Access.
18-25 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Configuring SGM User-Based Access When you specify a super user , keep in mind the follo wing considerat ions: • The user must exist i n the local /etc/passwd file.
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-26 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 – sgm webport – sgm xtermpath • If sgm aut htype is set to solari.
18-27 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM • Importing an SSL Ce rtificate to an SGM Client, pa ge 18-33 • Expo.
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-28 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 SGM gene rates the f ollowing files: – /opt/CSCOsgm/etc/ssl/server .ke y is the SGM server’ s priv ate key . Ensure that unauthorized per s onnel cannot access this k ey .
18-29 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM • T o use an existing signed ke y/certificate pair , log in as the root user on the SGM server and enter the follo wing command: # .
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-30 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Downloading the SGM Server’s Self-Signed SSL Certificate If you ha ve.
18-31 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM Launching the SGM Certificate Tool for SSL If you ha ve implemented Secure Sockets Layer (SSL) suppo rt in your SGM system, you c an launch th e SGM Certific ate T ool for SSL.
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-32 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Figur e 18-2 SGM Certificate T ool Dialog The SGM Certificate T ool dia.
18-33 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM Importing an SSL Certificate to an SGM Client If you ha ve implemented S.
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-34 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Use the Open dialog to locate th e SSL certificate that you w ant to import.
18-35 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM T o export an SSL certif icate, launch th e SGM SSL Certificate T ool, a.
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-36 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Related Topics: • Launching the SGM Certif icate T ool for SSL, page .
18-37 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM Figur e 18-5 Certificat e Infor mation Dialog.
Chapter 18 Configuring SGM Security Implementing SSL Support in SGM 18-38 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 The Certifi cate Information dialog displays the fol lowing detailed in.
18-39 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Implementing SSL Support in SGM Managing SSL Support in SGM SGM enables you to per form the follow ing t.
Chapter 18 Configuring SGM Security Limiting SGM Client Access to the SGM Server (Solaris Only) 18-40 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 • T o remov e an SSL certificate from the SGM client, launch the SGM SSL Certificate T ool. SGM lists each import ed certificate.
18-41 Cisco Signaling Gateway Manager User Guide OL-5742-01 Chapter 18 Configuring SGM Security Limiting SGM Client Access to the SGM Server (Solaris Only) Step 3 Create the ipaccess.conf fil e : • T o create t he ipaccess.conf file and add a client IP address to the list, enter the follo wing command: # .
Chapter 18 Configuring SGM Security Limiting SGM Client Access to the SGM Server (Solaris Only) 18-42 Cisco Signaling Gateway Mana ger User Guide OL-5742-01 Any changes you mak e to the ipaccess.conf file tak e effect when you restart the SGM server .
Ein wichtiger Punkt beim Kauf des Geräts Cisco Systems OL-5742-01 (oder sogar vor seinem Kauf) ist das durchlesen seiner Bedienungsanleitung. Dies sollten wir wegen ein paar einfacher Gründe machen:
Wenn Sie Cisco Systems OL-5742-01 noch nicht gekauft haben, ist jetzt ein guter Moment, um sich mit den grundliegenden Daten des Produkts bekannt zu machen. Schauen Sie zuerst die ersten Seiten der Anleitung durch, die Sie oben finden. Dort finden Sie die wichtigsten technischen Daten für Cisco Systems OL-5742-01 - auf diese Weise prüfen Sie, ob das Gerät Ihren Wünschen entspricht. Wenn Sie tiefer in die Benutzeranleitung von Cisco Systems OL-5742-01 reinschauen, lernen Sie alle zugänglichen Produktfunktionen kennen, sowie erhalten Informationen über die Nutzung. Die Informationen, die Sie über Cisco Systems OL-5742-01 erhalten, werden Ihnen bestimmt bei der Kaufentscheidung helfen.
Wenn Sie aber schon Cisco Systems OL-5742-01 besitzen, und noch keine Gelegenheit dazu hatten, die Bedienungsanleitung zu lesen, sollten Sie es aufgrund der oben beschriebenen Gründe machen. Sie erfahren dann, ob Sie die zugänglichen Funktionen richtig genutzt haben, aber auch, ob Sie keine Fehler begangen haben, die den Nutzungszeitraum von Cisco Systems OL-5742-01 verkürzen könnten.
Jedoch ist die eine der wichtigsten Rollen, die eine Bedienungsanleitung für den Nutzer spielt, die Hilfe bei der Lösung von Problemen mit Cisco Systems OL-5742-01. Sie finden dort fast immer Troubleshooting, also die am häufigsten auftauchenden Störungen und Mängel bei Cisco Systems OL-5742-01 gemeinsam mit Hinweisen bezüglich der Arten ihrer Lösung. Sogar wenn es Ihnen nicht gelingen sollte das Problem alleine zu bewältigen, die Anleitung zeigt Ihnen die weitere Vorgehensweise – den Kontakt zur Kundenberatung oder dem naheliegenden Service.