Using a Specific VLAN to Restrict Remote Access

Remote access using Telnet, TFTP, SNMP, and Web Management to RUCKUS ICX devices can be controlled using a specific VLAN ID.

By default, a RUCKUS device does not control remote management access based on the VLAN ID of the managing device. You can restrict remote management access to ports within a specific VLAN for the following access methods:

  • Telnet access

  • TFTP access

  • SNMP access

  • Web management access

The following steps demonstrate how to restrict remote management access for the above access methods. All steps are optional, and in no specific order.

  1. Enter global configuration mode.
    device# configure terminal
  2. Restrict Telnet access to clients in a specific VLAN.
    device(config)# telnet server enable vlan 10
    This step allows Telnet access to the device only to clients connected to ports within port-based VLAN 10.
  3. Restrict TFTP access to clients in a specific VLAN.
    device(config)# tftp client enable vlan 40
    This step allows TFTP access to the device only to clients connected to ports within port-based VLAN 40.
  4. Restrict SNMP access to clients in a specific VLAN.
    device(config)# snmp-server enable vlan 40
    This step allows SNMP access to the device only to clients connected to ports within port-based VLAN 40.
    Note: You can also configure SNMP access for a specific Ethernet port or range of ports. Refer to the RUCKUS FastIron Command Reference for more information on the snmp-server enable command.
  5. Restrict Web Management access to clients in a specific VLAN.
    device(config)# web-management enable vlan 20
    This step allows Web Management access to the device only to clients connected to ports within port-based VLAN 20.
    Note: You can also configure Web management access for an Ethernet port or a range of ports. Refer to the RUCKUS FastIron Command Reference for more information on the web-management command.