5-24 C70 CAPACITOR BANK PROTECTION AND CONTROL SYSTEM – INSTRUCTION MANUALPRODUCT SETUP CHAPTER 5: SETTINGS5the parameters for connecting the UR to the server have been configured, you can choose Server authentication onthe login screen of EnerVista.To configure Server authentication:1. In the EnerVista software, choose Device authentication and log in as Administrator.2. Configure the following RADIUS server parameters: IP address, authentication port, shared secret, and vendor ID.3. On the RADIUS server, configure the user accounts. Do not use the five pre-defined roles as user names (Administrator,Supervisor, Engineer, Operator, Observer) in the RADIUS server. If you do, the UR relay automatically provides theauthentication from the device.4. In the EnerVista software, choose Server authentication and log in using the user name and password configured onthe RADIUS server for Server authentication login.5. After making any required changes, log out.Pushbuttons (both user-control buttons and user-programmable buttons) located on the front panel can be pressed by anAdministrator or Engineer role. This also applies to the RESET button, which resets targets, where targets are errorsdisplayed on the front panel or the Targets panel of the EnerVista software. The RESET button has special behavior in that itallows these two roles to press it even when they are logged in through the RS232 port and not through the front panel.To reset the security event log and self-test operands:1. Log in as Supervisor (if the role is enabled) or Administrator (if the Supervisor role is disabled) and execute a clearsecurity command under Commands > Security > Clear Security.Syslog formatSystem logs are produced with the CyberSentry option. The format is as follows.Event Number — Event identification number (index)Date & Timestamp — UTC date and timeUsername — 255 chars maximum, but in the security log it is truncated to 20 charactersIP address — Device IP addressNOTICE The use of CyberSentry for devices communicating through an Ethernet-to-RS485 gateway is notsupported. Because these gateways do not support the secure protocols necessary to communicatewith such devices, the connection cannot be established. Use the device as a non-CyberSentrydevice.Users logged in through the front panel are not timed out and cannot be forcefully logged out by asupervisor. Roles logged in through the front panel that do no allow multiple instances (Administrator,Supervisor, Engineer, Operator) must switch to None (equivalent to a logout) when they are done inorder to log out.For all user roles except Observer, only one instance can be logged in at a time, for both login by frontpanel and software.NOTICE When changing settings offline, ensure that only settings permitted by the role that performs thesettings download are changed because only those changes are applied.Security log Event Number Date &TimestampUsername IP address Role Activity Value