management access

Configures access control for management protocols.
Syntax
management access { mac mac-address | src-ip ipv4-address | src-ipv6 ipv6-address } { allow |deny { all | log | snmp | { snmp-server { community | group | user } | name } |ssh | telnet | web } }
no management access { mac mac-address | src-ip ipv4-address | src-ipv6 ipv6-address } { allow |deny { all | log | snmp | { snmp-server { community | group | user } | name } | ssh | telnet | web } }
Command Default

By default, there are no restrictions on access for the management protocols.

Parameters
mac mac-address
Specifies a MAC address to which restrictions apply.
src-ip ipv4-address
Specifies a source IPv4 address and optional subnet mask in the form xxx.xxx.xxx.xxx (for example, 255.255.255.0) to which the restrictions apply.
src-ipv6 ipv6-address
Specifies an IPv6 address and optional subnet mask to which restrictions apply.
allow | deny
Specifies whether traffic for the protocol or protocols listed thereafter is allowed access or dropped.
all
Indicates the allow or deny action is applied to all management protocols in the list except snmp-server.
log
Indicates the allow or deny action is applied to log matching packets.
snmp
Indicates the allow or deny action is applied to incoming SNMP traffic for the specified address or addresses.
snmp-server { community | group | user } | name

Indicates the allow or deny action is applied to incoming SNMP server traffic for the specified address or addresses.

community: Indicates the community string.

group: Indicates the user security model group.

user: Indicates the user who can access the SNMP engine.

name: Indicates the name.

ssh
Indicates the allow or deny action is applied to incoming SSH traffic for the specified address or addresses.
telnet
Indicates the allow or deny action is applied to incoming Telnet traffic for the specified address or addresses.
web
Indicates the allow or deny action is applied to incoming HTTP traffic for the specified address or addresses.
Modes

Global configuration mode

Usage Guidelines

Note: Beginning in FastIron release 09.0.00, access control lists (ACLs) can no longer be applied to management protocols. Related binding commands are deprecated. The management access command is used instead to control incoming traffic from specific management protocols.

Note: The management access snmp-server configuration only supports source ipv4 and ipv6. It does not support MAC-based filtering.

The snmp-server with management access must not be combined with other protocols such as ssh, telnet, webui, and snmp. As group/user/community names are required for snmp-server but not for other protocols.

The no form of the command removes the management access command restrictions.

You can include a series of addresses of the same type or different types on a single command line.

You can include more than one type of management protocol on the same command line.

Use the show management access command to display configured management access restrictions for the ICX device.

Examples

The following example allows access to Telnet and SSH packets from the specified IPv4 address.

device# configure terminal
device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh

The following example drops all management traffic (Telnet, SSH, SNMP, HTTP) from the specified MAC address.

device(config)# management access mac CC:4E:24:D0:8B:81 deny all

The following example configures management access permissions for two groups of source IPv4 addresses and a MAC address. Management access is allowed for Telnet and SSH packets.

device(config)# management access src-ip 10.10.10.0 255.255.255.0 src-ip 1.1.1.1 255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh

The following example removes management access permissions for the group of IPv4 addresses specified.

device(config)# no management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh

The following example enables SNMP server community/group/user configurations.

device# configure terminal
device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server community test1
device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server group test1
device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server user test1
History
Release version Command history
09.0.00 This command was introduced.
09.0.10e This command was modified to add the snmp-server keyword.