CHAPTER 2: PRODUCT DESCRIPTION ORDER CODESG60 GENERATOR PROTECTION SYSTEM – INSTRUCTION MANUAL 2-72Table Notes:RW = read and write accessR = read accessSupervisor = RW (default), Administrator = R (default), Administrator = RW (only if Supervisor role is disabled)NA = the permission is not enforced by CyberSentry securityCyberSentry user authenticationThe following types of authentication are supported by CyberSentry to access the UR device:• Device Authentication (local UR device authenticates)• Server Authentication (RADIUS server authenticates)The EnerVista software allows access to functionality that is determined by the user role, which comes either from the localUR device or the RADIUS server.The EnerVista software has a device authentication option on the login screen for accessing the UR device. When the"Device" button is selected, the UR uses its local authentication database and not the RADIUS server to authenticate theuser. In this case, it uses its built-in roles (Administrator, Engineer, Supervisor, Observer, Operator, or Administrator andSupervisor when Device Authentication is disabled) as login names and the associated passwords are stored on the URdevice. As such, when using the local accounts, access is not user-attributable.In cases where user-attributable access is required especially to facilitate auditable processes for compliance reasons, useRADIUS authentication only.When the "Server" Authentication Type option is selected, the UR uses the RADIUS server and not its local authenticationdatabase to authenticate the user.No password or security information is displayed in plain text by the EnerVista software or UR device, nor is suchinformation ever transmitted without cryptographic protection.CyberSentry server authenticationThe UR has been designed to direct automatically the authentication requests based on user names. In this respect, localaccount names on the UR are considered as reserved and not used on a RADIUS server.The UR detects automatically whether an authentication request is to be handled remotely or locally. As there are five localaccounts possible on the UR, if the user ID credential does not match one of the five local accounts, the UR forwardsautomatically the request to a RADIUS server when one is provided.If a RADIUS server is provided, but is unreachable over the network, server authentication requests are denied. In thissituation, use local UR accounts to gain access to the UR system.2.3 Order codesThe order code is on the product label and indicates the product options applicable.The G60 is available as a 19-inch rack horizontal mount or reduced-size (¾) vertical unit. It consists of the followingmodules: power supply, CPU, CT/VT, contact input and output, transducer input and output, and inter-relaycommunications. Module options are specified at the time of ordering.The order codes shown here are subject to change without notice. See the web page for the product for the latest options.The order code depends on the mounting option (horizontal or vertical) and the type of CT/VT modules (enhanceddiagnostic CT/VT modules or HardFiber TM process bus module). The process bus module provides an interface toHardFiber Bricks.The R-GOOSE protocol described in IEC 61850-8-1 is available through the IEC 61850 software option. R-GOOSEsecurity requires the CyberSentry software option.