GE Multilin T60 Transformer Protection System 5-21
5 SETTINGS 5.2 PRODUCT SETUP
5
Supervisory
PATH: SETTINGS  PRODUCT SETUP  SECURITY SUPERVISORY
The Supervisory menu settings are available for Supervisor role only or if the Supervisor role is disabled then for the
Administrator role only.
DEVICE AUTHENTICATION: This setting is enabled by default, meaning "Yes" is selected. When enabled, Device Authen-
tication with roles is enabled. When this setting is disabled, the UR only authenticates to the AAA server (Radius). How-
ever, the Administrator and Supervisor (when enabled) remain active even after device authentication is disabled and their
only permission is to re-enable device authentication. To re-enable device authentication, the Supervisor unlocks the
device for setting changes, then the Administrator re-enables device authentication.
BYPASS ACCESS: The bypass security feature provides an easier access, with no authentication and encryption for those
special situations when this is considered safe. Only the Supervisor, or the Administrator when the Supervisor role is dis-
abled, can enable this feature.
The bypass options are as follows:
• Local — Bypasses authentication for push buttons, keypad, RS232, and RS485
• Remote — Bypasses authentication for Ethernet
• Local and Remote — Bypasses authentication for push buttons, keypad, RS232, RS485, and Ethernet
LOCK RELAY: This setting uses a Boolean value (Enable/Disable) to indicate if the device accepts setting changes and
whether the device can receive a firmware upgrade. This setting can be changed only by the Supervisor role, if it is enabled
or by the Administrator if the Supervisor role is disabled. The Supervisor role enables this setting for the relay to start
accepting setting changes or command changes or firmware upgrade. After all the setting changes are applied or com-
mands executed, the Supervisor disables to lock setting changes.
Example: If this setting is "Yes" and an attempt is made to change settings or upgrade the firmware, the UR device denies
the setting changes and denies upgrading the firmware. If this setting is "No", the UR device accepts setting changes and
firmware upgrade.
This role is disabled by default.
FACTORY SERVICE MODE:    When enabled (meaning "Yes" is selected) the device can go into factory service mode. For
this setting to become enabled a Supervisor authentication is necessary. The default value is Disabled.
 SUPERVISORY
 
DEVICE 
AUTHENTICATION:Yes
Range: Yes, No
MESSAGE
BYPASS ACCESS:
Disabled
Range: Local, Remote, Local and Remote, Disabled 
MESSAGE
LOCK RELAY:
Disabled
Range: Enabled, Disabled 
MESSAGE
FACTORY SERVICE:
MODE: Disabled
Range: Enabled, Disabled 
MESSAGE
 SELF TESTS
 
See below
MESSAGE
SUPERVISOR ROLE:
Disabled
Range: Enabled, Disabled
MESSAGE
SERIAL INACTIVITY
TIMEOUT: 1 min
Range: 1 to 9999 minutes 
MODE FRONT PANEL OR SERIAL (RS232, RS485) ETHERNET
Normal mode Authentication — Role Based Access Control (RBAC)
and passwords in clear
Authentication — RBAC and passwords encrypted
SSH tunneling
Bypass access mode No passwords for allowed RBAC levels No passwords for allowed RBAC levels
No SSH tunneling