
SSH and HTTP/HTTPS access. The administrator can select either a preconfigured security profile or create a
custom profile. For more information, see Security on page 18.
Authentication
Authentication can be performed locally, with One Time Passwords (OTP), a remote Kerberos, LDAP, NIS,
RADIUS, TACACS+ authentication server or a DSView 3 server. The console server also supports remote group
authorizations for the LDAP, RADIUS and TACACS+ authentication methods. Fallback mechanisms are also
available.
Any authentication method configured for the console server or the ports is used for authentication of any user
who attempts to log in through Telnet, SSH or the web manager. For more information, see Authentication on
page 41.
VPN based on IPSec with NAT traversal
If IPSec is enabled in the selected security profile, an administrator can use the VPN feature to enable secure
connections. IPSec encryption with optional NAT traversal (which is configured by default) creates a secure
tunnel for dedicated communications between the console server and other computers that have IPSec installed.
ESP and AH authentication protocols, RSA Public Keys and Shared Secret aresupported. For more information,
see IPSec(VPN) on page 28.
Packet filtering
An administrator can configure a console server to filter packets like a firewall. Packet filtering is controlled by
chains, which are named profiles with user-defined rules. The console server filter table contains a number of
built-in chains that can be modified but not deleted. An administrator can also create and configure new chains.
SNMP
If SNMP is enabled in the selected security profile, an administrator can configure the Simple Network
Management Protocol (SNMP) agent on the console server to answer requests sent by an SNMP management
application.
The console server SNMP agent supports SNMP v1/v2 and v3, MIB-II and Enterprise MIB. For more information,
see SNMP Configuration on page 29.
NOTE: The text files with the Enterprise MIB (ACS6000-MIB.asn) and the TRAP MIB (ACS6000-TRAP-MIB.asn) are available in
the appliance under the /usr/local/mibs directory.
Data logging, notifications, alarms and data buffering
An administrator can set up data logging, notifications and alarms to alert administrators of problems with email,
SMS, SNMP trap or DSView 3 software notifications. An administrator can also store buffered data locally,
remotely or with DSView 3 management software. Messages about the console server and connected servers or
devices can also be sent to syslog servers.
Chapter 1: Introduction 3
Commentaires sur ces manuels