Controlling traffic on management ports in a VLAN or VRF
Prior to
FastIron 8.0.50, management traffic on both in-band and out-of-band (OOB) management interfaces
depended on membership in the management VLAN or VRF. Now you can exclude these interfaces
for management traffic, which includes IPv6 Router Advertisement (RA) traffic on a
Layer 2 image, and IPv6 RA, HTTP, NTP, SSH, and Telnet traffic on a Layer 3 image.
management exclude command in global configuration mode to exclude traffic types as in the following
examples.
To exclude inband IPv6 RA traffic on a switch image:
device(config)# management exclude ipv6ra inband
To exclude all OOB traffic on a switch or router image:
device(config)# management exclude all inband
To exclude SSH OOB traffic on a router image:
device(config)# management exclude ssh oob
Use the
show management traffic exclusion command to confirm a configuration, as in the following example:
device# show management traffic exclusion Port App Inband all oob all
Note: The
management exclude command is mutually exclusive with respect to either the
ip ssh strict-management-vrf or the
telnet strict-management-vrf commands. If the
management exclude command is also configured, outbound SSH or Telnet connections are not blocked. If
the management interface VRF and the management VRF are the same, then the
ip ssh strict-management-vrf and
telnet strict-management-vrf commands do not stop a connection initiated from an OOB management interface. In
this case, the user must execute the
management exclude all oob,
management exclude ssh oob, or
management exclude telnet oob command, as appropriate, to stop a connection.