Creating an Administrator

When you need to perform the permission/domain specific management of the ATIC Management center, you can select an administrator group to obtain the permission on this administrator group, select the resources, and set the IP address segment that can log in the ATIC Management center.

Context

Only the default administrator admin can perform one-click alarm clearing, configuration restoration, all deployment and public configurations.

Procedure

  1. Choose System > System Administrators > Administrators.
  2. Click .

    NOTE:
    Ensure that the flash plug-in has been installed on the browser. Otherwise, the page cannot be displayed.

  3. Set the parameters of the new administrator, as described in Table 1.

    Table 1 Parameters of the new administrator

    Parameter

    Description

    Value

    Username

    User name for logging in to the ATIC Management center. After an administrator is created, its user name cannot be changed.

    -

    Authentication Mode

    Mode for authenticating the login of a system administrator to the ATIC Management center.

    • Password authentication is a local authentication mode that the user name and password are directly specified on the ATIC Management center server.

      Advantages of the password authentication: high speed, and low operation expenditure. Disadvantages of the password authentication: low security, and storage capacity restricted by the ATIC Management center server hardware conditions.

    • RADIUS authentication means that the user information is configured on the Remote Authentication Dial In User Service (RADIUS) server, and the ATIC Management center communicates with the RADIUS server as the client and it performs the remote authentication through the RADIUS protocol.

      Advantages of the RADIUS authentication: High security and reliability when the third-party server is used for authentication because it supports the resending mechanism and standby server mechanism. Disadvantages of the RADIUS authentication: High operation expenditure as it requires the deployment of the RADIUS server.

      NOTE:

      When RADIUS authentication is adopted, you need to configure the RADIUS server. For details, see Configuring the Authentication Server.

    Password

    Password for logging in to the ATIC Management center when the password authentication is used.

    The password must contain no less than eight characters and must contain letters, digits, and special characters at the same time by default. A specific password is subject to the password policy configured in the system security policy. For details about the specific requirements, see Configuring the System Security Policy.

    Confirm password

    Enter the password again. The two passwords must be identical.

    The parameter value must be the same as that in Password.

    Description

    Brief description of the administrator, helping identifying the administrator.

    -

  4. Configure the permissions, resources, and allowed IP address segment for the administrator.

    NOTE:

    By default, the administrator has no associated administrator group and no resources, and can access the ATIC Management center from any IP addresses. You must specify an administrator group to the administrator, and select the resources and IP address segment as required.

    • Click the Select Administrator Group tab, and select an administrator group for the administrator.

      When multiple administrator groups are selected, the permission of the administrator is the permission collection of all the selected administrator groups.

    • Click the Select Resource tab, and select manageable resources according to Resource Type.

      NOTE:
      Ensure that the flash plug-in has been installed on the browser. Otherwise, the page cannot be displayed.
    • Click the Select Login Network Segment tab. Perform the following operations to configure the IP address segment list and then select one allowed IP address segment for the administrator.

      • Click , set Start IP address, End IP address, and Description, and click OK.

      • Select an IP address segment, click to modify Start IP address, End IP address, and Description, and then click OK.

      • Select the IP address segment to be deleted and click to delete it.

  5. Click OK.

    The newly created administrator is displayed in Administrators.

Follow-up Procedure

When RADIUS authentication is adopted for the administrator, you need to configure the RADIUS server. For details, see Configuring the Authentication Server.


Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.