Restricting Remote Access Using IP Addresses or MAC Addresses

You can specify which management protocols are allowed access to the switch using specific IP addresses or MAC addresses.

The following management protocols can be allowed or denied access to an ICX switch based on IPv4, IPv6, or MAC source addresses:

  • SNMP
  • SSH
  • Telnet
  • Web (HTTP)

You can use the management access command to restrict access for one or more protocols to a specified source address or set of source addresses. As an option, you can also specify that matching traffic generate a syslog entry.

Perform the following steps to configure address-based access control for management protocols.

  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
  2. Enter the management access command followed by the keyword for the type of source address:
    • Enter src-ip for an IPv4 source address.
    • Enter src-ip6 for an IPv6 source address.
    • Enter mac for a source MAC address.
  3. Following the source address keyword, enter the source address.
    Note: You can enter a series of source addresses of the same or different types on the same command line.
    Note: Use a subnet mask for an IPv4 address in the format A.B.C.D xxxx.xxxx.xxxx (for example, src-ip 10.10.10.1 255.255.255.255, or 10.10.10.1/32).
  4. On the same line, specify whether to allow or deny traffic for the source address or addresses, and designate the management protocol or protocols to which the action applies.
    Note: You can apply the same action to more than one protocol.
    • snmp: Apply the action to SNMP packets.
    • ssh: Apply the action to SSH packets.
    • telnet: Apply the action to Telnet packets.
    • web: Apply the action to HTTP packets.
    • all: Apply the action to all the management protocols in this list.
  5. (Optional) On the same line, enter the keyword log to generate a syslog entry for traffic that matches the management access statement.
  6. (Optional) Enter the show management access command to display the management access controls applied to the ICX switch.
    device# show management access 
    src-ip 10.10.10.0/255.255.255.0 src-ip 1.1.1.1/255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh
    mac CC:4E:24:D0:8B:81 allow snmp
            

The following example allows access to Telnet and SSH packets from the specified IPv4 address.

device# configure terminal
device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh

The following example drops all management traffic (Telnet, SSH, SNMP, HTTP) from the specified MAC address.

device(config)# management access mac CC:4E:24:D0:8B:81 deny all

The following example configures management access permissions for two groups of source IPv4 addresses and a MAC address. Management access is allowed for Telnet and SSH packets.

device(config)# management access src-ip 10.10.10.0 255.255.255.0 src-ip 1.1.1.1 255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh

The following example removes management access permissions for the group of IPv4 addresses specified.

device(config)# no management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh