EasyManuals Logo
Home>Cisco>Network Router>ASR 5000 Series

Cisco ASR 5000 Series Administration Guide

Cisco ASR 5000 Series
508 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #143 background imageLoading...
Page #143 background image
If no information related to LI server addresses is received for that subscriber, LI server addresses will not be
restricted.
A maximum of five LI server addresses are supported via an authenticating agent.Important
The ability to restrict destination addresses for LI content and event delivery using RADIUS attributes is
supported only for PDSN and HA gateways.
Important
Modifying Intercepts
One LI administrator can access and/or modify the intercepts created by another LI administrator. Whenever
an intercept is added, removed or modified, an event log is displayed across LI administrators about the change.
An SNMP trap is also generated.
Adding, Modifying and Removing Users
It is considered uncommon for a user to be added or removed from the system. Likewise, it is considered
uncommon for a user's privileges to modified. However, if the system is compromised, it is common for
attackers to add or remove a privileged user, raise their privileges or lower the privileges of others.
As a general rule, lower privileged users should not be allowed to increase their privileges or gain access to
sensitive data, such as passwords, which were entered by higher privileged users.
The system can only detect changes in users and user attributes, such as privilege level, when these users
are configured through the system.
Important
Notification of Users Being Added or Deleted
Users with low level authorization should not be able to create users with high level authorization. However,
if a malicious actor were to be able to create a high level authorized user, they could then delete the other high
level authorized users, thereby locking them out of the system.
The following SNMP traps notify an administrator when users are added or removed:
starLocalUserAdded indicates that a new local user account has been added to the system.
starLocalUserRemoved indicates that a local user account has been removed from the system.
Notification of Changes in Privilege Levels
Whenever a user's privilege level is increased or decreased, an SNMP notification will be sent out. A malicious
actor may gain access to more privileged commands by somehow promoting" their privileges. Once this is
ASR 5500 System Administration Guide, StarOS Release 21.4
111
System Security
Modifying Intercepts

Table of Contents

Other manuals for Cisco ASR 5000 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASR 5000 Series and is the answer not in the manual?

Cisco ASR 5000 Series Specifications

General IconGeneral
BrandCisco
ModelASR 5000 Series
CategoryNetwork Router
LanguageEnglish

Related product manuals