management access
management access
{
mac
mac-address
|
src-ip
ipv4-address
|
src-ipv6
ipv6-address
}
{
allow
|deny
{
all
|
log
|
snmp
|
{
snmp-server
{
community
|
group
|
user
}
|
name
}
|ssh
|
telnet
|
web
}
}no management access
{
mac
mac-address
|
src-ip
ipv4-address
|
src-ipv6
ipv6-address
}
{
allow
|deny
{
all
|
log
|
snmp
|
{
snmp-server
{
community
|
group
|
user
}
|
name
}
|
ssh
|
telnet
|
web
}
}By default, there are no restrictions on access for the management protocols.
- src-ip ipv4-address
- Specifies a source IPv4 address and optional subnet mask in the form xxx.xxx.xxx.xxx (for example, 255.255.255.0) to which the restrictions apply.
- src-ipv6 ipv6-address
- Specifies an IPv6 address and optional subnet mask to which restrictions apply.
- allow | deny
- Specifies whether traffic for the protocol or protocols listed thereafter is allowed access or dropped.
-
- all
- Indicates the
allow or deny action is applied to all management protocols in
the list except
snmp-server. - snmp
- Indicates the allow or deny action is applied to incoming SNMP traffic for the specified address or addresses.
- snmp-server { community | group | user } | name
-
Indicates the allow or deny action is applied to incoming SNMP server traffic for the specified address or addresses.
community: Indicates the community string.
group: Indicates the user security model group.
user: Indicates the user who can access the SNMP engine.
name: Indicates the name.
- ssh
- Indicates the allow or deny action is applied to incoming SSH traffic for the specified address or addresses.
- telnet
- Indicates the allow or deny action is applied to incoming Telnet traffic for the specified address or addresses.
Global configuration mode
management access command is used instead to
control incoming traffic from specific management protocols. Note: The management access
snmp-server configuration only supports source ipv4 and ipv6.
It does not support MAC-based filtering.
The snmp-server
with management access must not be combined with other protocols such as
ssh, telnet, webui, and snmp. As group/user/community names are required for
snmp-server but not for other protocols.
The no form of the command
removes the management access command restrictions.
You can include a series of addresses of the same type or different types on a single command line.
You can include more than one type of management protocol on the same command line.
Use the show management access
command to display configured management access restrictions for the ICX device.
The following example allows access to Telnet and SSH packets from the specified IPv4 address.
device# configure terminal device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh
The following example drops all management traffic (Telnet, SSH, SNMP, HTTP) from the specified MAC address.
device(config)# management access mac CC:4E:24:D0:8B:81 deny all
The following example configures management access permissions for two groups of source IPv4 addresses and a MAC address. Management access is allowed for Telnet and SSH packets.
device(config)# management access src-ip 10.10.10.0 255.255.255.0 src-ip 1.1.1.1 255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh
The following example removes management access permissions for the group of IPv4 addresses specified.
device(config)# no management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh
The following example enables SNMP server community/group/user configurations.
device# configure terminal device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server community test1 device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server group test1 device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server user test1