Controlling Traffic on Management Ports in a VLAN or VRF
Prior to FastIron 8.0.50, management traffic
on both in-band and out-of-band (OOB) management interfaces depended on membership
in the
management VRF. Now you can exclude these interfaces for management traffic, which
includes
IPv6 RA, HTTP, NTP, SSH, and Telnet traffic on a Layer 3 image.
management exclude command in global configuration mode to exclude traffic types as in the following
examples.
To exclude inband IPv6 RA traffic on a router image:
device(config)# management exclude ipv6ra inband
To exclude SSH OOB traffic on a router image:
device(config)# management exclude ssh oob
Note: The
management exclude
command is mutually exclusive with respect to the management vrf strict
command. If the management
exclude command is also configured, outbound SSH or Telnet connections
are not blocked. If the management interface VRF and the management VRF are the
same, then the management
vrf strict command does not stop a connection initiated from an OOB
management interface. In this case, the user must execute the management exclude all
oob, management exclude ssh oob, or management exclude telnet
oob command, as appropriate, to stop a connection.