13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Accessing <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>Managing login permissionsThis section explains how to manage login permissions and contains <strong>the</strong> following topics:●●●●●●Security overview — overview <strong>of</strong> <strong>the</strong> <strong>G350</strong>’s internal security mechanism and how it canoperate in conjunction with a RADIUS au<strong>the</strong>ntication systemManaging users and passwords — explanation <strong>of</strong> <strong>the</strong> users, passwords, and accessprivileges, and instructions on how to define new usersSSH protocol support — explanation <strong>of</strong> SSH au<strong>the</strong>ntication and instructions on how toconfigure SSH au<strong>the</strong>ntication parametersSCP protocol support — explanation <strong>of</strong> SCP au<strong>the</strong>ntication and instructions on how toconfigure SCP au<strong>the</strong>ntication parametersRADIUS au<strong>the</strong>ntication — instructions on how to configure <strong>the</strong> <strong>G350</strong> to work with anexternal RADIUS server802.1x protocol — instructions on how to configure 802.1x protocolSecurity overviewThe <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong> includes a security mechanism through which <strong>the</strong> systemadministrator defines users and assigns each user and username and a password. Each user isassigned a privilege level. The user’s privilege level determines which commands <strong>the</strong> user canperform.In addition to its basic security mechanism, <strong>the</strong> <strong>G350</strong> supports secure data transfer via SSHand SCP.The <strong>G350</strong> can be configured to work with an external RADIUS server to provide userau<strong>the</strong>ntication. When RADIUS au<strong>the</strong>ntication is enabled on <strong>the</strong> <strong>G350</strong>, <strong>the</strong> RADIUS serveroperates in conjunction with <strong>the</strong> <strong>G350</strong> security mechanism. When <strong>the</strong> user enters a username,<strong>the</strong> <strong>G350</strong> first searches its own database for <strong>the</strong> username. If <strong>the</strong> <strong>G350</strong> does not find <strong>the</strong>username in its own database, it establishes a connection with <strong>the</strong> RADIUS server, and <strong>the</strong>RADIUS server provides <strong>the</strong> necessary au<strong>the</strong>ntication services.The <strong>G350</strong> also uses <strong>the</strong> 802.1x protocol in conjunction with EAP within EAPOL and overRADIUS to provide a means <strong>of</strong> au<strong>the</strong>nticating and authorizing users attached to a LAN port,and <strong>of</strong> preventing access to that port in cases where <strong>the</strong> au<strong>the</strong>ntication process fails.36 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!