
Security Issues
Introduction
1-6
Enterprise Configuration Manager
User’s Guide
Security Issues
Enterprise Configuration Manager is a powerful tool. Because it gives users
the ability to reconfigure any number of devices on a network, the
administrator should use extreme caution when setting up user-privileges.
ECM is designed so that network administrators can restrict the types of
operations that a user can perform. For example, you may want to prevent
inexperienced users from creating or loading configurations — these are the
two operations, when misused, which could cause damage to a functioning
network. With ECM’s security features, the administrator can set up accounts
for these users allowing them to view and verify but not create and load
configurations.
There are two ways to provide security when working with Enterprise
Configuration Manager: SPECTRUM security and SNMP security:
• SPECTRUM security controls a user’s access to all network management
operations for any device.
• SNMP security, on the other hand, controls a user’s access to a single
device.
SPECTRUM and SNMP security are described in the following sections.
For specific details about setting up community strings in SPECTRUM, refer
to the SPECTRUM Administrator’s Reference.
SPECTRUM Security
In SPECTRUM, the system administrator maintains security by issuing users
a community string. This community string can have one or more parts, each
part specifying permissions for a certain “community.” For example, the
community string ADMIN,0:ECM,3 gives the user access to all SPECTRUM
administration privileges but only View, Verify, and Load privileges in ECM.
The following rules apply to community strings:
• The SPECTRUM community string ADMIN,0 - 2 (without an additional
ECM community string) gives users full privileges in ECM.
• All ECM community strings require the ADMIN,0-9 community name as
a prefix. The correct format is ADMIN,0-9:ECM,0-8.
• ECM community strings give users the privileges that are specified in the
ECM part of the community string. It does not matter if the ADMIN part
of the community string specifies greater or fewer privileges.
Comentarios a estos manuales