
Introduction – Important InformationIntroduction – Important Information
Authorization Assignment
COMpact 5010 VoIP/5020 VoIP - Firmware version 4.0 - Configuration Manual 06 08/11 9
Authorization Levels for Accessing the Web Inter-
face
To prevent important settings from being changed by mistake or by
unauthorized persons, there are different authorization levels in the
PBX. Access to the Web interface on the PBX is divided into three
authorization levels: Administrator (admin), sub-administrator (sub-
admin) and user.
Each of these authorization levels has a user name and a PIN (see
table). This information needs to be entered when you log into the
Web interface (for internal and external access to the PBX).
Important: All PINs in the PBX are unique; that means that it is not
possible to assign the same PIN twice in the PBX.
Do not use dates of birth or dates as PINs. This makes it easy for an
attacker to find out the correct PIN. PINs which are easy to guess,
such as 111111 or 123456, should also be avoided.
As the PINs can also be entered via telephone, only digits are possi-
ble. A PIN is always 6 digits long.
After entering the wrong PIN three times to access the Web interface,
there is a timeout of 60 seconds. During this time, no PIN entry is pos-
sible.
No PINs are pre-defined in the default factory settings.
Administrator (Admin)
The administrator can be the authorized dealer or the administrator
of the PBX.
The administrator has access to the configuration manager without
restrictions. With this access, he can configure the PBX completely
but he can also release PBX functions with the PBX dongle. This
authorization level also allows changing the other PINs without know-
ing them as well as the assignment of access authorizations.
Sub-administrator (Sub-admin)
A sub-administrator (up to four are possible) is an internal supervisor.
This is the person that has the role of a local administrator at the loca-
tion of the PBX. On the page Administration User PINs, this func-
tional level can be assigned to four individual internal subscribers on
the PBX. Therefore a sub-administrator is also a user at the same
time and can also log-in as such in the Web interface.
The access authorizations to the Web interface are assigned to the
sub-administrators by the administrator according to the local
requirements. These assignments are made on the page Administra-
tion Access Authorizations. With the exception of some pages
(e.g., Administration Access Authorizations), the entire configura-
tion manager or only some individual pages can be released to the
sub-administrators.
Each of the four possible sub-administrators has the same access
and modification authorizations.
Note: If the sub-administrator enters his internal telephone number
as his user name, this registration is recognized as a user log-in and
the Web interface is presented in user mode.
User
The user is any internal subscriber of the PBX that may receive addi-
tional authorizations by being assigned a user PIN.
The access authorizations to the Web interface are assigned to the
user by the administrator according to local requirements. This
assignment/setting is done on the page Administration Access
Authorizations. The possible range of page releases is limited to a
very small number of individual subscriber and group settings.
Each user has the same access authorizations. Modification rights
may differ depending on the profiles (see Profiles and Properties on
page 10).
Authorization Levels for Operation via Telephone
On the system telephones COMfortel 1100/1500/2500/2500 AB/VoIP
2500 AB, the three authorization levels of the PBX with the corre-
sponding PINs are also used. The authorizations are set individually
for each telephone in the telephone menu or with the corresponding
configuration manager or PC program COMfortel Set (see the man-
ual for the system telephone). It is possible to release all the functions
even for use without a password (authorization level “guests”).
In addition, the PINs of the PBX are needed for the operation of some
functions with the standard telephone:
The user PIN mainly offers access to a few personal functions such
as private calls and the activation of the Call Restrictor and
Deblocker. The user PIN is used to remotely control some of the func-
tions on the individual telephone if the programming sequence is
used on another internal telephone.
The admin PIN and the sub-admin PIN offer access to functions such
as setting call allowance accounts and recording announcements.
External Access to the PBX
The PBX is protected from external access (dial-up to the PBX via
PPP/remote configuration) by the admin PIN or by two separate
PINs. First of all, you need one of the three PINs that you also use for
internal access to log into the Web interface. For the preceding
required dial-up, you need to enter the “external” user name and the
external PIN (or admin user name and admin PIN) in the connection
dialogue.
Besides this, the external PIN is needed for operating some functions
such as Follow-me, Remote control and Room Monitoring from an
external telephone (Remote Programming). Dial-up is done using a
special telephone number, the remote programming telephone
number. The PBX accepts the call automatically and the PIN or the
programming sequence is entered via DTMF.
Note: The external PIN cannot be used for logging into the Web inter-
face.
Authorization Assignment
Corresponding PIN Corresponding User Name
Authorization level
Administrator
Admin PIN (is specified in the configuration assistant during initial sys-
tem set-up; may be changed on the page Administration Server con-
figuration)
“admin” (in the default factory setting; may be
changed on the page Administration Server
configuration)1
1. If the configuration manager of the PBX is to be reached from the Internet (via http or better via https), you should also change the user name of the administrator
(admin) for reasons of security.
Authorization level
Sub-administrator
Sub-Admin PIN (corresponds to the user PIN of the corresponding
sub-administrator)
“sub-admin” (not changeable; is valid for all four
sub-administrators)
Authorization level
User
User PIN (assigned to each user on the page Administration User
PINs)
internal telephone number of the user
External Access External PIN (assigned to the page COMset Global settings
Remote configuration)
“external” (not changeable)