Security related system parameters

Last Updated : Oct 29, 2012 |

Determines when Avaya Communication Manager reports a security violation. Many of the fields on this screen repeat for each type of security violation. They are explained once here, but the usage is the same for all.

Example command: change system-parameters security

Security related system parameters: page 1

Hide Post-Dialing DTMF On List Trace

Enable this field to display asterisk (*) characters in place of digits in the output of the list trace command. The default value of this field is n.

SECURITY VIOLATION NOTIFICATION PARAMETERS

Announcement Extension

The announcement extension where the Security Violation Notification (SVN) announcement resides. The server running Communication Manager calls the referral destination, then plays this announcement upon answer.

Originating Extension

The extension that initiates the referral call in the event of a security violation. It also sends the appropriate alerting message or display to the referral destination. If notification for more than one type of security violation is established, a different extension must be assigned to each one. When Communication Manager generates a referral call, this extension and the type of violation appear on the display at the referral destination.

Referral Destination

The extension that receives the referral call when a security violation occurs. The referral destination telephone must have a display, unless it is an Announcement Extension. The extension can be the telephone, attendant console, or vector directory number (VDN) that receives the referral call for each type of violation. This can be the same extension for all type of violations.

The Announcement Extension field is used for a VDN. Call Vectoring Time-of-Day routing is used to route the referral call to different destinations based on the time of day or the day of the week.

SVN Authorization Code Violation Notification Enabled

Enables or disables Authorization Code Violation Security Notification. By using SVN Remote Access Violation Notification Enabled, you can do the following:

  • Establish parameters for remote access security violations.

  • Enable or disable the feature.

A remote access violation occurs if a user enters incorrect barrier codes. The system cannot disable remote access following a security violation unless SVN Remote Access Violation Notification Enabled field is enabled.

SVN Login (Violation Notification, Remote Access, Authorization Code) Enabled

Enables or disables login violation notification. If enabled, Communication Manager sends a notification when a login violation occurs.

SVN Remote Access Violation Notification Enabled

Use this field to enable or disable Remote Access Violation Notification. Use with SVN Authorization Code Violation Notification Enabled to enable or disable remote access security violations. A remote access violation occurs if a user enters incorrect barrier codes. The system cannot disable remote access following a security violation unless this field is enabled.

Time Interval

Valid Entry

Usage

0:01 to 7:59

This time range, in conjunction with Login Threshold, determines if a security violation has occurred.

The range for the time interval is one minute to eight hours, entered in the screen x:xx. For example, one minute is entered as 0:01 and seven and one-half hours is entered as 7:30.

Security related system parameters: page 2

ACCESS SECURITY GATEWAY PARAMETERS

These fields are available only if Access Security Gateway (ASG) is enabled for the system.

INADS

Indicates whether or not any entry attempt through a port that is a direct connection to the Initialization and Administration System (INADS) receives a challenge response. INADS is used to remotely initialize and administer Communication Manager

MGR1

Indicates whether or not any entry attempt through a port that is a direct connection to the system administration and maintenance access interface located on the processor receives a challenge response.

NET

Indicates whether or not any entry attempt through a port that is a dialed-in or dialed-out connection to the Network Controller receives a challenge response.

Translation-ID Number Mismatch Interval (days)

Valid Entry

Usage

1 to 90

The number of days the system allows access to system administration commands. When this interval expires, only init logins have the ability to execute system administration commands to modify translation data.

REMOTE MANAGED SERVICES

Port Board Security Notification

Enables or disables port board denial of service notification. Available only if RMS Feature Enabled is enabled.

Port Board Security Notification Interval

Valid Entry

Usage

60 to 3600 in increments of 10

The interval in seconds between port board Denial of Service notifications (traps). Default is 60.

Note:

There is no delay before the first trap is sent. The interval administered in this field applies only to the period between the sending of the traps.

Available only if Remote Managed Services and Port Board Security Notification are enabled.

RMS Feature Enabled

Enables or disables Remote Managed Services.

SECURITY VIOLATION NOTIFICATION PARAMETERS

SVN Station Security Code Violation Notification Enabled

Use this field to enable or disable the security violation notification for Station Security Codes. Station Security Codes are used to validate logins to a particular extension.

The default value is n.

STATION SECURITY CODE VERIFICATION PARAMETERS

Minimum Station Security Code Length

Valid Entry

Usage

3 to 8

The minimum required length of the station security codes. Longer codes are more secure. If station security codes are used for external access to telecommuting features, the minimum length should be seven or eight.

Receive Unencrypted from IP Endpoints

Allows or blocks unencrypted data from IP endpoints.

Security Code for Terminal Self Administration Required

Specifies whether or not a Personal Station Access code is required to enter the Self-Administration mode.