Restricting Web Management Access

You can restrict Web management access to include only management functions on a RUCKUS device that is acting as an IPv6 host, or restrict access so that the RUCKUS host can be reached by a specified IPv6 device.

Restricting Web Management Access Examples

Web management access can be restricted using the following methods:

  • IPv6 ACLs
  • IPv6 host names

Access Restricted by Specifying an IPv6 ACL

You can specify an IPv6 ACL that restricts Web management access to management functions on the device that is acting as the IPv6 host.

device(config)# ipv6 access-list acl12
device(config-ipv6-access-list acl12)# deny ipv6 host 2000:2383:e0bb::2/128 any log
device(config-ipv6-access-list acl12)# deny ipv6 30ff:3782::ff89/128 any log
device(config-ipv6-access-list acl12)# deny ipv6 3000:4828::fe19/128 any log
device(config-ipv6-access-list acl12)# permit ipv6 any any
device(config-ipv6-access-list acl12)# exit
device(config)# web access-group ipv6 acl12

Access Restricted to an IPv6 Host

You can restrict Web management access to the device to the IPv6 host whose IP address you specify. No other device except the one with the specified IPv6 address can access the Web Management Interface.

device(config)# web client ipv6 3000:2383:e0bb::2/128

The IPv6 address you specify must be in hexadecimal format using 16-bit values between colons as documented in RFC 2373.