Management Applications Supporting Management VRFs
This section explains the management VRF support provided by the management applications.
SNMP Server
When the management VRF is configured, the SNMP server receives SNMP requests and sends SNMP responses only through the ports belonging to the management VRF and through the out-of-band management port.
Any change in the management VRF configuration becomes immediately effective for the SNMP server.
SNMP Trap Generator
When the management VRF is configured, the SNMP trap generator sends traps to trap hosts through the ports belonging to the management VRF and through the out-of-band management port.
Any change in the management VRF configuration takes effect immediately for the SNMP trap generator.
SSH Server
When the management VRF is configured, the incoming SSH connection requests are allowed only from the ports belonging to the management VRF and from the out-of-band management port. Management VRF enforcement occurs only while a connection is established.
Telnet Client
To allow the incoming Telnet connection requests
only from the management VRF and not from the out-of-band management port, enter
the
management vrf
command followed by the VRF name and the keyword strict as shown
in the following example.
device(config)# management vrf telnet10 strict
RADIUS Client
When the management VRF is configured, the RADIUS client sends RADIUS requests or receives responses only through the ports belonging to the management VRF and through the out-of-band management port.
Any change in the management VRF configuration takes effect immediately for the RADIUS client.
TACACS+ Client
When the management VRF is configured, the TACACS+ client establishes connections with TACACS+ servers only through the ports belonging to the management VRF and the out-of-band management port.
For the TACACS+ client, a change in the management VRF configuration does not affect the existing TACACS+ connections. The changes are applied only to new TACACS+ connections.
TFTP
When the management VRF is configured, TFTP sends or receives data and acknowledgments only through ports belonging to the management VRF and through the out-of-band management port.
Any change in the management VRF configuration takes effect immediately for TFTP. You cannot change the management VRF configuration while a TFTP file transfer is in progress.
SCP
SCP uses SSH as the underlying transport. The behavior of SCP is similar to the SSH server.
Syslog
When the management VRF is configured, the Syslog module sends log messages only through the ports belonging to the management VRF and the out-of-band management port.
Any change in the management VRF configuration takes effect immediately for Syslog.