Enabling Management Access Based on a Port-based VLAN
You can restrict management access so that only devices with ports in a specific port-based VLAN have access. Clients connected to ports that are not in the VLAN are denied management access. VLAN-based access control works in conjunction with other access control methods.
The following considerations apply to port-based VLAN access control.
- As in a switched network, the TACACS server and the SSH client should be in the same VLAN.
- If the TACACS server and the SSH client are not in the same VLAN, the response expected
from the TACACS server should be sent in the same VLAN as configured by the
tacacs-server enable vlancommand. With this configuration, the TACACS server can be in a different VLAN and still allow SSH connections in a routed network. - The
tacacs-server enable vlancommand should not be configured in a network that uses dynamic routing because the TACACS server response might be routed on any path.
The following example allows TACACS server management access only to clients in VLAN 10.
device# configure terminal device(config)# tacacs-server enable vlan 10