Configuration Examples of Restricting Remote Access Using ACLs

Remote access to management functions can be an efficient way to manage your devices. When you need to restrict this access, you can use ACLs.

The following examples describe how to restrict remote access to a RUCKUS ICX device from Telnet, SSH, the Web Management interface, and SNMP.

The following methods for restricting remote access are supported:

  • Using standard ACLs to restrict Telnet, Web Management Interface, or SNMP access
  • Allowing remote access only from specific IP addresses
  • Allowing Telnet and SSH access only from specific MAC addresses
  • Allowing remote access only to clients connected to a specific VLAN
  • Specifically disabling Telnet, Web Management Interface, or SNMP access to the device

Using ACLs to Restrict Telnet Access

The following example configures a restrictive ACL with permit entries, but without a permit any entry at the end of the ACL. Telnet access is given only to the IP addresses in the permit entries; all other IP addresses are denied Telnet access.

device# configure terminal
device(config)# ip access-list standard acl11 
device(config-std-ipacl-acl11)# deny ip host 10.157.22.32
device(config-std-ipacl-acl11)# deny ip 10.157.23.0 0.0.0.255
device(config-std-ipacl-acl11)# deny ip 10.157.24.0 0.0.0.255
device(config-std-ipacl-acl11)# deny ip 10.157.25.0/24
device(config-std-ipacl-acl11)# permit 10.157.25.0/24
device(config-std-ipacl-acl11)# exit
device(config)# telnet access-group acl11
device(config)# write memory 

Using ACLs to Restrict SNMP Access

The following examples restricts SNMP access to the device using ACLs. The snmp-server community command is used in conjunction with ip access-list command entries. The example configures ACLs 25 and 30 and applies them to SNMP community strings, which users must enter to gain SNMP access. ACL 25 is used to control read-only (get) access using the "public" community string. ACL 30 is used to control read-write (get/set) access using the "private" community string.

Note: When the snmp-server community command is configured, all incoming SNMP packets are validated first by their community strings and then by their bound ACLs.
device# configure terminal
device(config)# ip access-list standard 25 
device(config-std-ipacl-25)# deny host 10.157.22.98 log
device(config-std-ipacl-25)# deny 10.157.23.0 0.0.0.255 log
device(config-std-ipacl-25)# deny 10.157.24.0 0.0.0.255 log 
device(config-std-ipacl-25)# permit any
device(config-std-ipacl-25)# exit
device(config)# ip access-list standard 30 
device(config-std-ipacl-30)# deny 10.157.25.0 0.0.0.255 log
device(config-std-ipacl-30)# deny 10.157.26.0/24 log
device(config-std-ipacl-30)# permit any
device(config-std-ipacl-30)# exit
device(config)# snmp-server community public ro 25 
device(config)# snmp-server community private rw 30
device(config)# write memory 

Using ACLs to Restrict SSH Access

The following example configures an ACL that restricts SSH access to the device.

These commands configure standard numbered ACL 12, which is applied as the access list for SSH access. The device denies SSH access from the IP addresses listed in ACL 12 and permits SSH access from all other IP addresses. Without the last ACL entry for permitting all packets, this ACL would deny SSH access from all IP addresses.

device(config)# ip access-list standard 12 
device(config-std-ipacl-12)# deny host 10.157.22.98 log
device(config-std-ipacl-12)# deny 10.157.23.0 0.0.0.255 log
device(config-std-ipacl-12)# deny 10.157.24.0/24 log
device(config-std-ipacl-12)# permit any
device(config-std-ipacl-12)# exit
device(config)# ssh access-group 12
device(config)# write memory 
Note: In this example, the command telnet access-group 12 could have been used to apply the ACL configured in the example for Telnet access. You can use the same ACL multiple times.

The following example configures standard IPv4 numbered access list 10 that permits only two specific hosts, denies and logs a third host, and denies all other hosts.

device# configure terminal
device(config)# ip access-list standard 10 
device(config-std-ipacl-10)# permit host 10.168.144.241
device(config-std-ipacl-10)# deny host 10.168.144.242 log
device(config-std-ipacl-10)# permit host 10.168.144.243
device(config-std-ipacl-10)# deny any
device(config-std-ipacl-10)# exit
device(config)# ssh access-group 10

Using ACLs to Restrict Web Management Access

The following example configures an ACL that restricts Web management access to the device. ACL 12 is applied as the access list for Web management access to deny Web management access from the IP addresses listed in ACL 12 and permit Web management access from all other IP addresses. Without the last ACL entry for permitting all packets, this ACL would deny Web management access from all IP addresses.

device(config)# ip access-list standard 12 
device(config-std-ipacl-12)# deny host 209.157.22.98 log
device(config-std-ipacl-12)# deny 209.157.23.0 0.0.0.255 log
device(config-std-ipacl-12)# deny 209.157.24.0/24 log
device(config-std-ipacl-12)# permit any
device(config-std-ipacl-12)# exit
device(config)# web access-group 12
device(config)# write memory