Restricting Remote Access Using IP Addresses or MAC Addresses
The following management protocols can be allowed or denied access to an ICX switch based on IPv4, IPv6, or MAC source addresses:
You can use the management access
command to restrict access for one or more protocols to a specified source address
or set of source addresses. As an option, you can also specify that matching traffic
generate a syslog entry.
Perform the following steps to configure address-based access control for management protocols.
- Enter global configuration mode.
- Enter the
management accesscommand followed by the keyword for the type of source address: - Following the source address
keyword, enter the source address.Note: You can enter a series of source addresses of the same or different types on the same command line.Note: Use a subnet mask for an IPv4 address in the format A.B.C.D xxxx.xxxx.xxxx (for example, src-ip 10.10.10.1 255.255.255.255, or 10.10.10.1/32).
- On the same line, specify
whether to allow or deny traffic for the
source address or addresses, and designate the management protocol or protocols
to which the action applies.Note: You can apply the same action to more than one protocol.
- (Optional) On the same line, enter the keyword log to generate a syslog entry for traffic that matches the management access statement.
- (Optional) Enter the
show management accesscommand to display the management access controls applied to the ICX switch.
The following example allows access to Telnet and SSH packets from the specified IPv4 address.
device# configure terminal device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow telnet ssh
The following example drops all management traffic (Telnet, SSH, SNMP, HTTP) from the specified MAC address.
device(config)# management access mac CC:4E:24:D0:8B:81 deny all
The following example configures management access permissions for two groups of source IPv4 addresses and a MAC address. Management access is allowed for Telnet and SSH packets.
device(config)# management access src-ip 10.10.10.0 255.255.255.0 src-ip 1.1.1.1 255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh