Management Applications Supporting Management VRFs

This section explains the management VRF support provided by the management applications.

SNMP Server

When the management VRF is configured, the SNMP server receives SNMP requests and sends SNMP responses only through the ports belonging to the management VRF and through the out-of-band management port.

Any change in the management VRF configuration becomes immediately effective for the SNMP server.

SNMP Trap Generator

When the management VRF is configured, the SNMP trap generator sends traps to trap hosts through the ports belonging to the management VRF and through the out-of-band management port.

Any change in the management VRF configuration takes effect immediately for the SNMP trap generator.

Note: The SNMP source interface configuration command snmp-server trap-source must be compatible with the management VRF configuration.

SSH Server

When the management VRF is configured, the incoming SSH connection requests are allowed only from the ports belonging to the management VRF and from the out-of-band management port. Management VRF enforcement occurs only while a connection is established.

To allow the incoming SSH connection requests only from the management VRF and not from the out-of-band management port, enter the following command.

device(config)# ip ssh strict-management-vrf

The ip ssh strict-management-vrf command is applicable only when the management VRF is configured. If not, the command issues the following warning message.

Warning - Management-vrf is not configured.
Note: For the SSH server, changing the management VRF configuration or configuring the ip ssh strict-management-vrf command does not affect the existing SSH connections. The changes are be applied only to new incoming connection requests.

Telnet Client

To allow the incoming Telnet connection requests only from the management VRF and not from the out-of-band management port, enter the following command.

device(config)# telnet strict-management-vrf

RADIUS Client

When the management VRF is configured, the RADIUS client sends RADIUS requests or receives responses only through the ports belonging to the management VRF and through the out-of-band management port.

Any change in the management VRF configuration takes effect immediately for the RADIUS client.

Note: The RADIUS source interface configuration command ip radius source-interface must be compatible with the management VRF configuration.

TACACS+ Client

When the management VRF is configured, the TACACS+ client establishes connections with TACACS+ servers only through the ports belonging to the management VRF and the out-of-band management port.

For the TACACS+ client, a change in the management VRF configuration does not affect the existing TACACS+ connections. The changes are applied only to new TACACS+ connections.

Note: The TACACS+ source interface configuration command ip tacacs source-interface must be compatible with the management VRF configuration.

TFTP

When the management VRF is configured, TFTP sends or receives data and acknowledgments only through ports belonging to the management VRF and through the out-of-band management port.

Any change in the management VRF configuration takes effect immediately for TFTP. You cannot change in the management VRF configuration while a TFTP file transfer is in progress.

Note: The TFTP source interface configuration command ip tftp source-interface must be compatible with the management VRF configuration.

SCP

SCP uses SSH as the underlying transport. The behavior of SCP is similar to the SSH server.

Syslog

When the management VRF is configured, the Syslog module sends log messages only through the ports belonging to the management VRF and the out-of-band management port.

Any change in the management VRF configuration takes effect immediately for Syslog.

Note: The Syslog source interface configuration command ip syslog source-interface must be compatible with the management VRF configuration.