DX NetOps

 View Only

  • 1.  DX NetOps NFA – Password Policy Capabilities (Current Versions)

    Posted Apr 14, 2026 12:16 PM
    Good morning team,
     
    Could you please confirm which password policy capabilities are available in DX NetOps NFA (current versions of DX NFA)?
     
    Specifically, I need to verify if the platform supports the following:
     
    1) Minimum password length
    2) Password change on first login
    3) Password composition
    4) Periodic password change
    5) Allowed failed login attempts
    6) Password history
    7) Session lockout for inactivity
    8) Temporary password expiration
    9) Account lockout for inactivity
    10) Log
     
    Thanks!


    -------------------------------------------


  • 2.  RE: DX NetOps NFA – Password Policy Capabilities (Current Versions)

    Broadcom Employee
    Posted 30 days ago

    NFA uses the same SSO module as NetOps Portal.

    When NFA is added to NetOps Portal, Portal takes over all User administration including password policies mentioned in Portal docs.

    Users are synced from Portal to NFA.  SO when using NFA direct login page, it's using same user DB as Portal.

    -------------------------------------------



  • 3.  RE: DX NetOps NFA – Password Policy Capabilities (Current Versions)

    Posted 29 days ago
    Good day, team.
     
    Thank you for your previous response.
     
    I'd like to clarify my question for greater precision. The scenario to be validated is an environment dedicated solely to DX NetOps NFA, without integration with NetOps Portal and without any additional DX NetOps components.
     
    Could you please confirm which password policy features are available directly in DX NetOps NFA under this scenario?
     
    Specifically, I need to validate if NFA supports the following:
     
    Minimum password length
    Password change on first login
    Password complexity
    Periodic expiration / forced change
    Failed login attempts allowed / account lockout
    Password history
    Logout due to inactivity
    Temporary password expiration
    Account lockout due to inactivity
    Security logs
     
    Thank you very much for your support.
    -------------------------------------------



  • 4.  RE: DX NetOps NFA – Password Policy Capabilities (Current Versions)

    Broadcom Employee
    Posted 29 days ago

    What version of NetOps/NFA are you using?

    Even when only using NFA, we require NetOps Portal machine, as we've redone administration/etc and that is only available via NetOps Portal.

    If you run SsoConfig on NFA command window, do you see the NetOps Portal Local Password Authentication option.  If not, then no, you can't control from the NFA side.

    -------------------------------------------



  • 5.  RE: DX NetOps NFA – Password Policy Capabilities (Current Versions)

    Posted 25 days ago

    It used to be possible to run NFA as a standalone - as in without CA PC (CA Performance Center) - the predecessor to what is now the NetOps Portal. However, this is no longer possible - and hasn't been possible for many NFA versions (as in you would have to go back to a version from the dim distant past 3-5+ years ago that would no longer be supported to do so).

    I had a customer that was insistent to do NFA without the Portal several years ago (they wanted to use the NetQos Performance Center - the predecessor to CA PC!). However, they quickly found the errors of their ways when it came to support - as in their setup wasn't supported and the only way forward was to swap out the Windows NPC box for a Linux CA PC box and run NPC...

    These days, if you jump onto the NFA Console you will find that, as Jeff mentions, the majority of management tasks end up linking to a page in the NetOps Portal (it used to be that they would work in the Console but no longer). The main reason for this (other than a shift in the code) is that the NFA Console is heavilty dependent on the use of Adobe Flash - which is a completely dead product and your security guys would have a field day if you tried to install an earlier version of it. This will NOT change (as in the way forward is to use DX Flow!). You would have to have a particular version of Firefox with a particular version of Flash in order to do so nowadays (yes, I did work out how to do it but the information is now old and with loads of security issues that it is not worth sharing).

    So, to summarise - yes, you will need a NetOps Portal box to run NFA. No, it can't run on the NFA Console since the NFA Console runs under Windows and the Portal runs under Linux. No, you should NOT put it on the NFA Harvester either (since that can run under Linux) since the loadings that both applications have would kill the server itself (no matter what spec of the combined box you have).

    Regards,

    Ed

    -------------------------------------------