Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Configuring a Network Device collaborative Protection Profile for an Authorized Administrator

An account for root is always present in a configuration and is not intended for use in normal operation. In the evaluated configuration, the root account is restricted to the initial installation and configuration of the evaluated device.

An NDcPP Version 3.0e authorized administrator must have all permissions, including the ability to change the router configuration.

To configure an authorized administrator:

  1. Create a login class named security-admin with all permissions.
  2. Configure hashed algorithm SHA256 or SHA512 for plain-text passwords. SHA512 is the default hashing algorithm.
    Note:

    For your security devices, the default password algorithm is sha512, and it is not necessary to configure the plain-text passwords for the QFX5120-48YM device.

  3. Commit the changes.
  4. Define your NDcPPv3.0e user authorized administrator.

    or

    To configure public key authentication and keyboard-interactive authentication:

    Note:

    ssh-ed25519 is not supported in FIPS mode although it is shown as a configurable option.

    To delete a configured login credential, use the following command:

    The set commands used to configure the credentials as shown above can be repeated to overwrite the currently configured credentials.

    The Keyboard-Interactive Based authentication for SSH is supported by default and needs no additional configuration apart from a password being configured for the user. Providing multifactor authentication mechanism would require the use of an external AAA server, which is outside the CC scope, as a result of which the keyboard-interactive authentication method works similarly to the password-based method in the evaluated configuration.

  5. Commit the changes.