CHAPTER 5: SETTINGS PRODUCT SETUPD30 LINE DISTANCE PROTECTION SYSTEM – INSTRUCTION MANUAL 5-195Table 5-4: General security settingsConfirm RADIUSAuthentication(Shared) SecretConfirmation of the shared secret. Theentry displays as asterisks.See thePasswordRequirementssection245 characters N/A - AdministratorSetting name Description Minimum Maximum Default Units MinimumpermissionSession Lockout Number of failed authentications before thedevice blocks subsequent authenticationattempts for the lockout period0 (lockoutdisabled)99 3 - AdministratorSession LockoutPeriodThe period in minutes that a user is preventedfrom logging in after being locked out0 (no period) 9999 3 min AdministratorSyslog Server IPAddressThe IP address of the target Syslog server towhich all security events are transmitted0.0.0.0 223.255.255.2540.0.0.0 - AdministratorSyslog Server PortNumberThe UDP port number of the target syslogserver to which all security events aretransmitted1 65535 514 - AdministratorDeviceAuthenticationWhen enabled, local Device authenticationwith roles is allowed. When disabled, the URonly authenticates to the AAA server (RADIUS).NOTE: Administrator and Supervisor (if stillenabled) remain active even after Deviceauthentication is disabled. The only permissionfor local Administrator is to re-enable Deviceauthentication when Device authentication isdisabled. To re-enable Device authentication,the Supervisor unlocks the device for settingchanges, and then the Administrator can re-enable Device authentication.Disabled Enabled Enabled - AdministratorFirmware Lock(via Lock Relay)Indicates if the device receives firmwareupgrades. If Enabled and the firmwareupgrade attempt is made, the device deniesthe upgrade and displays an error messagethat the lock is set. On each firmware upgrade,this setting goes back to the default.The Lock Relay setting blocks settings andfirmware updates.Disabled Enabled Enabled - AdministratorFactory ServiceModeWhen enabled, the device can go into factoryservice mode. To enable, Supervisorauthentication is necessary.Disabled Enabled Disabled - Supervisor(Administratorwhen Supervisoris disabled)Restore to Defaults Sets the device to factory defaults No Yes No - AdministratorSupervisor Role When enabled, the Supervisor role is active. Toenable, Administrator authentication isnecessary. When disabled, the Supervisor roleis inactive. To disable, Supervisorauthentication is necessary.Disabled Enabled Enabled - Administrator toenable andSupervisor todisableRADIUS user names Ensures that RADIUS user names are not thesame as local/device role namesSee RADIUSserverdocumentsSeeRADIUSserverdocuments- AdministratorPassword Local/device roles except for Observer arepassword-protected. All RADIUS users arepassword-protected.See thePasswordRequirementssection earlierin this chapterSee thefollowingpasswordsection forrequirementsChangeMe1#Text The specifiedrole andAdministrator,except forSupervisor,where it is onlyitselfSetting name Description Minimum Maximum Default Units Minimumpermission