Configuration Examples of Restricting Remote Access Using ACLs
The following examples describe how to restrict remote access to a RUCKUS ICX device from Telnet, SSH, the Web Management interface, and SNMP.
The following methods for restricting remote access are supported:
- Using standard ACLs to restrict Telnet, Web Management Interface, or SNMP access
- Allowing remote access only from specific IP addresses
- Allowing Telnet and SSH access only from specific MAC addresses
- Allowing remote access only to clients connected to a specific VLAN
- Specifically disabling Telnet, Web Management Interface, or SNMP access to the device
Using ACLs to Restrict Telnet Access
The following example configures a restrictive ACL with permit entries, but without
a
permit any entry at the end of the ACL. Telnet access is given only to the IP addresses in the
permit entries; all other IP addresses are denied Telnet access.
device# configure terminal device(config)# ip access-list standard acl11 device(config-std-ipacl-acl11)# deny ip host 10.157.22.32 device(config-std-ipacl-acl11)# deny ip 10.157.23.0 0.0.0.255 device(config-std-ipacl-acl11)# deny ip 10.157.24.0 0.0.0.255 device(config-std-ipacl-acl11)# deny ip 10.157.25.0/24 device(config-std-ipacl-acl11)# permit 10.157.25.0/24 device(config-std-ipacl-acl11)# exit device(config)# telnet access-group acl11 device(config)# write memory
Using ACLs to Restrict SNMP Access
The following examples restricts SNMP access to
the device using ACLs. The snmp-server community command is used in conjunction with ip access-list command
entries. The example configures ACLs 25 and 30 and applies them to SNMP community
strings, which users must enter to gain SNMP access. ACL 25 is used to control
read-only (get) access using the "public" community string. ACL 30 is used to
control read-write (get/set) access using the "private" community string.
snmp-server community command is configured, all incoming SNMP packets are validated first by their community
strings and then by their bound ACLs.
device# configure terminal device(config)# ip access-list standard 25 device(config-std-ipacl-25)# deny host 10.157.22.98 log device(config-std-ipacl-25)# deny 10.157.23.0 0.0.0.255 log device(config-std-ipacl-25)# deny 10.157.24.0 0.0.0.255 log device(config-std-ipacl-25)# permit any device(config-std-ipacl-25)# exit device(config)# ip access-list standard 30 device(config-std-ipacl-30)# deny 10.157.25.0 0.0.0.255 log device(config-std-ipacl-30)# deny 10.157.26.0/24 log device(config-std-ipacl-30)# permit any device(config-std-ipacl-30)# exit device(config)# snmp-server community public ro 25 device(config)# snmp-server community private rw 30 device(config)# write memory
Using ACLs to Restrict SSH Access
The following example configures an ACL that restricts SSH access to the device.
These commands configure standard numbered ACL 12, which is applied as the access list for SSH access. The device denies SSH access from the IP addresses listed in ACL 12 and permits SSH access from all other IP addresses. Without the last ACL entry for permitting all packets, this ACL would deny SSH access from all IP addresses.
device(config)# ip access-list standard 12 device(config-std-ipacl-12)# deny host 10.157.22.98 log device(config-std-ipacl-12)# deny 10.157.23.0 0.0.0.255 log device(config-std-ipacl-12)# deny 10.157.24.0/24 log device(config-std-ipacl-12)# permit any device(config-std-ipacl-12)# exit device(config)# ssh access-group 12 device(config)# write memory
telnet access-group 12
could have been used to apply the ACL configured in the example for Telnet access.
You can use the same ACL multiple times. The following example configures standard IPv4 numbered access list 10 that permits only two specific hosts, denies and logs a third host, and denies all other hosts.
device# configure terminal device(config)# ip access-list standard 10 device(config-std-ipacl-10)# permit host 10.168.144.241 device(config-std-ipacl-10)# deny host 10.168.144.242 log device(config-std-ipacl-10)# permit host 10.168.144.243 device(config-std-ipacl-10)# deny any device(config-std-ipacl-10)# exit device(config)# ssh access-group 10
Using ACLs to Restrict Web Management Access
The following example configures an ACL that restricts Web management access to the device. ACL 12 is applied as the access list for Web management access to deny Web management access from the IP addresses listed in ACL 12 and permit Web management access from all other IP addresses. Without the last ACL entry for permitting all packets, this ACL would deny Web management access from all IP addresses.
device(config)# ip access-list standard 12 device(config-std-ipacl-12)# deny host 209.157.22.98 log device(config-std-ipacl-12)# deny 209.157.23.0 0.0.0.255 log device(config-std-ipacl-12)# deny 209.157.24.0/24 log device(config-std-ipacl-12)# permit any device(config-std-ipacl-12)# exit device(config)# web access-group 12 device(config)# write memory