User's Manual 8. Web-Based Management
Version 6.8 65 Mediant 500L MSBR
 To prevent user access after a specific number of failed logins:
1. From the 'Deny Access On Fail Count' drop-down list, select the number of failed
logins after which the user is prevented access to the device for a user-defined time
(see next step).
2. In the 'Deny Authentication Timer' field, enter the interval (in seconds) that the user
needs to wait before a new login attempt from the same IP address can be done after
reaching the number of failed login attempts (defined in the previous step).
Notes:
• For security, it's recommended that you change the default username and
password of the pre-configured users (i.e., Security Administrator and Monitor
users).
• The Security Administrator user can change all attributes of all Web user
accounts. Web users with access levels other than Security Administrator can
change only their username and password.
• To restore the two Web user accounts to default settings (usernames and
passwords), set the ini file parameter ResetWebPassword to 1.
• To log in to the Web interface with a different Web user, click the Log off button
and then login with with a different username and password.
• You can set the entire Web interface to read-only (regardless of Web user access
levels), by using the ini file parameter DisableWebConfig (see ''Web and Telnet
Parameters'' on page 779).
• You can define additional Web user accounts using a RADIUS server (see
''RADIUS Authentication'' on page 221).
8.3.1 Basic User Accounts Configuration
This section describes basic Web user account configuration. This is relevant only if the
two default, pre-configured Web user accounts--Security Administrator ("Admin") and
Monitor ("User")--are sufficient for your management scheme.
The Web user account parameters that can be modified depends on the access level of the
currently logged-in Web user:
Table 8-10: Allowed Modifications per Web User Level
Logged-in User Web User Level Allowed Modifications
Security
Administrator
(Default) Security Administrator Username and password
Monitor Username, password, and access level
Monitor
(Default) Security Administrator None
Monitor Username and password
Notes:
• The username and password can be a string of up to 19 characters and are case-
sensitive.
• When only the basic user accounts are being used, up to two users can be
concurrently logged in to the Web interface, and they can be the same user.