Controlling Traffic on Management Ports in a VLAN or VRF
Prior to
FastIron 8.0.50, management traffic on both in-band and out-of-band (OOB) management interfaces
depended on membership in the management VLAN or VRF. Now you can exclude these interfaces
for management traffic, which includes IPv6 Router Advertisement (RA) traffic on a
Layer 2 image, and IPv6 RA, HTTP, NTP, SSH, and Telnet traffic on a Layer 3 image.
management exclude command in global configuration mode to exclude traffic types as in the following
examples.
To exclude inband IPv6 RA traffic on a switch image:
device(config)# management exclude ipv6ra inband
To exclude all OOB traffic on a switch or router image:
device(config)# management exclude all inband
To exclude SSH OOB traffic on a router image:
device(config)# management exclude ssh oob
Note:
Verify
note contents for FI 09.0.00.
The management exclude
command is mutually exclusive with respect to the management vrf strict
command. If the management
exclude command is also configured, outbound SSH or Telnet connections
are not blocked. If the management interface VRF and the management VRF are the
same, then the management
vrf strict command does not stop a connection initiated from an OOB
management interface. In this case, the user must execute the management exclude all
oob, management exclude ssh oob, or management exclude telnet
oob command, as appropriate, to stop a connection.