Restricting Web Management Access
Restricting Web Management Access Examples
Web management access can be restricted using the following methods:
Access Restricted by Specifying an IPv6 ACL
You can specify an IPv6 ACL that restricts Web management access to management functions on the device that is acting as the IPv6 host.
device(config)# ipv6 access-list acl12 device(config-ipv6-access-list acl12)# deny ipv6 host 2000:2383:e0bb::2/128 any log device(config-ipv6-access-list acl12)# deny ipv6 30ff:3782::ff89/128 any log device(config-ipv6-access-list acl12)# deny ipv6 3000:4828::fe19/128 any log device(config-ipv6-access-list acl12)# permit ipv6 any any device(config-ipv6-access-list acl12)# exit device(config)# web access-group ipv6 acl12
Access Restricted to an IPv6 Host
You can restrict Web management access to the device to the IPv6 host whose IP address you specify. No other device except the one with the specified IPv6 address can access the Web Management Interface.
device(config)# web client ipv6 3000:2383:e0bb::2/128
The IPv6 address you specify must be in hexadecimal format using 16-bit values between colons as documented in RFC 2373.