User's Manual

MDS 05-6302A01, Rev. A MDS Mercury 16E Technical Manual 31
4.2 CONFIGURE SECURITY FEATURES &
INTEGRATION WITH A RADIUS SERVER
Device Management Interface Configuration
Using the Configuration - Security page, each of the device management
interfaces (HTTP, SNMP, SSH, telnet) can be enabled or disabled. For
secure installations, it is recommended that 1) the Telnet interface be
disabled, 2) the SNMP agent run in SNMPv3 mode, 3) the web server
be configured for HTTPS with MD5 digest.
User Accounts
Each Mercury transceiver has a set of local user accounts available via
console terminal management. The local accounts are as listed in the
chart below:
NOTE: In case of a lost password and an inability to login to the trans-
ceiver, see “TROUBLESHOOTING” on Page 36 for details
on resetting the password.
In addition to the local user accounts, the Mercury transceiver can be
configured to use a RADIUS server for centralized user account
management. The Configuration - Security page is used to configure the
User Auth Method to RADIUS. If the User Auth Fallback parameter is set to
Local, then the local user account information will be used if the
RADIUS server (and secondary server if configured) is unreachable.
Username Default Password Access level
operator operator Read-only access to configuration parameters and status and
performance metrics and statistics. (Applies only to Console
Terminal Management.)
admin admin Read and write access to all configuration parameters and read
access to status and performance metrics and statistics