management source-interface
management source-interface
{
ethernet
stack-id/slot/port
|
lag
number
|
loopback
number
|
management
number
|
ve
number
}
{
protocol
{
all
|
manager
|
ntp
|
radius
|
snmp
|
ssh
|
syslog
|
tacacs
|
telnet
|
tftp
}
}management source-interface
management{
protocol
{manager
|
radius
|
ssh
|
syslog
|
tacacs
|
telnet
|
tftp
}
}no management source-interface
{
ethernet
stack-id/slot/port
|
lag
number
|
loopback
number
|
management
number
|
ve
number
}
{
protocol
{
manager
|
radius
|
ssh
|
syslog
|
tacacs
|
telnet
|
tftp
}
}no management source-interface
management
number{
protocol
{
manager
|
radius|
ssh
|
syslog
|
tacacs
|
telnet
|
tftp
}
}By default, the source interface is not enabled.
- ethernet stack-id/slot/port
-
Specifies the Ethernet interface address used for setting the source IP address.
- lag number
- Specifies the link aggregation group (LAG) interface address used for setting the source IP address.
- management number
- Specifies the management interface address used for setting the source IP address.
- ve number
- Specifies the Virtual Ethernet (VE) interface address used for setting the source IP address.
- protocol manager
- Specifies the interface to be used by SmartZone ICX-Management to manage the ICX device in on-premises installations.
- protocol radius
- Configures an interface as the source IP address from which the RADIUS client sends RADIUS requests or receives responses.
- protocol syslog
- Configures an interface as the source IP address from which the syslog module sends log messages.
- protocol tacacs
- Configures an interface as the source IP address from which the TACACS+ client establishes connections with TACACS+ servers.
- protocol telnet
- Sets the lowest-numbered IP address configured on an interface as the source for all Telnet packets.
Global configuration mode
The no form of the command
resets the source address of the packet as the lowest-numbered IP address on the
interface that sends the packet.
You can configure an ICX Layer 3 switch so that it always uses the lowest-numbered IP address on a specific Ethernet, loopback, or virtual interface as the source address for a specific type of packet. When a source interface is configured, the Layer 3 switch uses the same IP address as the source for all packets of the specified type, regardless of the ports that actually send the packets.
If your server is configured to accept packets only from specific IP addresses, you can use this configuration to simplify configuration of the server by configuring the ICX device so that it always sends the packets from the same link or source address.
If you specify a loopback interface as the single source for specified packets, servers can receive the packets regardless of the states of individual links. Thus, if a link to the server becomes unavailable, but the client or server can be reached through another link, the client or server still receives the packets, and the packets still have the source IP address of the loopback interface.
When a management VRF is configured, the specified management protocol or application requests and receives responses only through ports belonging to the management VRF and through the out-of-band management port. When a source interface is configured, management applications use the lowest configured IP address of the specified interface as the source IP address in all the outgoing packets. If the configured interface is not part of the management VRF, the response packet does not reach the destination. If the compatibility check fails while either the management VRF or the source interface is being configured, an error message is displayed; however, the configuration command is accepted.
The RADIUS source interface configuration must be compatible with the management VRF configuration. Any change in the management VRF configuration takes effect immediately for the RADIUS client.
The lowest IP address configured on the specified interface is sent to ICX-Management in the manager query. If there is no source interface configuration, the management IP address is sent.
The no management
source-interface protocol manager command removes the source interface
configuration and returns to the default source interface (the management port).
For NTP, the specified interface is
used for the source address for all packets sent to all destinations. If a source
address is to be used for a specific association, use the source keyword in the peer or server command.
The syslog source interface configuration must be compatible with the management VRF configuration. Any change in the management VRF configuration takes effect immediately for syslog.
The TACACS+ source interface configuration must be compatible with the management VRF configuration.
For the TACACS+ client, a change in the management VRF configuration does not affect the existing TACACS+ connections. The changes are applied only to new TACACS+ connections.
The TFTP source interface configuration must be compatible with the management VRF configuration.
Any change in the management VRF configuration takes effect immediately for TFTP. You cannot make changes in the management VRF configuration while TFTP is in progress.
The following example configures an Ethernet interface as the source IP address for the RADIUS client.
device# configure terminal device(config)# management source-interface ethernet 1/1/1 protocol radius
The following example configures a loopback interface as the source IP address for the RADIUS client.
device(config)# management source-interface loopback 1 protocol radius
The following example configures an Ethernet port as the source interface for ICX-Management.
device(config)# management source-interface ethernet 1/1/3 protocol manager
The following example configures a virtual interface as the source interface for ICX-Management.
device(config)# management source-interface ve 10 protocol manager
The following example configures a management interface as the source IP address for the syslog module to send log messages.
device(confg)# management source-interface management 1 protocol syslog