Disabling Remote Access Methods
-
Telnet access—You can use a Telnet client to access the CLI of the device over the network. If you do not plan to use the CLI over the network, you can disable Telnet access to prevent others from establishing CLI sessions with the device.
-
TFTP—By default, TFTP client access is enabled. You can globally disable TFTP to block TFTP client access.
-
SNMP access—You can disable SNMP management of the device.
-
Web management access—If you want to prevent access to the device through the Web Management Interface, you can disable the Web Management Interface.
Note: As soon as you disable the Web Management Interface, the device stops responding to Web management sessions. If you make this change using your Web browser, your browser can contact the device, but the device will not reply once the change takes place. - Web management access by HP ProCurve Manager—By default, TCP ports 80 and 280 are enabled on the RUCKUS ICX device. TCP port 80 (HTTP) allows access to the device Web Management Interface. TCP port 280 allows access to the device by HP ProCurve Manager.
- Enter global configuration mode.
- Disable Telnet access.
If you disable Telnet access, you will not be able to access the CLI except through a serial connection to the management module.
- Disable TFTP access.
When TFTP is disabled, users are prohibited from using the copy tftp command to copy files to the system flash. If you enter the
copy tftpcommand while TFTP is disabled, the system will reject the command and display an error message. To reenable TFTP client access after it has been disabled, use theno tftp disablecommand. - Disable SNMP management of the device
If you disable SNMP access, you will not be able to use an SNMP-based management application.
- Disable web management access through both http access and https access.
- The
no web-managementcommand disables both TCP ports. To disable only port 280 and leave port 80 enabled, add the hp-top-tools keyword.