Enabling Management Access Based on a Port-based VLAN

You can restrict management access so that only devices with ports in a specific port-based VLAN have access. Clients connected to ports that are not in the VLAN are denied management access. VLAN-based access control works in conjunction with other access control methods.

The following considerations apply to port-based VLAN access control.

  • As in a switched network, the TACACS+ server and the SSH client should be in the same VLAN.
  • If the TACACS+ server and the SSH client are not in the same VLAN, the response expected from the TACACS+ server should be sent in the same VLAN as configured by the tacacs-server enable vlan command. With this configuration, the TACACS+ server can be in a different VLAN and still allow SSH connections in a routed network.
  • The tacacs-server enable vlan command should not be configured in a network that uses dynamic routing because the TACACS+ server response might be routed on any path.

The following example allows TACACS+ server management access only to clients in VLAN 10.

device# configure terminal
device(config)# tacacs-server enable vlan 10