10-11
Using Authorized IP Managers
Building IP Masks
Figure 10-5. Example of How the Bitmap in the IP Mask Defines Authorized Manager Addresses
IP Mask
255
255
255
249
In this example (figure 10-5, below), the IP mask allows a group of up to
4 management stations to access the switch. This is useful if the only
devices in the IP address group allowed by the mask are management
stations. The “249” in the 4th octet means that bits 0 and 3 - 7 of the 4th
octet are fixed. Conversely, bits 1 and 2 of the 4th octet are variable. Any
value that matches the authorized IP address settings for the fixed bits is
allowed for the purposes of IP management station access to the switch.
Thus, any management station having an IP address of 10.28.227.121, 123,
125, or 127 can access the switch.
Authorized
IP Address
10
28
227
125
1st
Octet
2nd
Octet
3rd
Octet
4th
Octet
Manager-Level or Operator-Level Device Access
4th Octet of IP Mask:
4th Octet of Authorized IP Address:
249
5
Bit Numbers
Bit
7
Bit
6
Bit
5
Bit
4
Bit
3
Bit
2
Bit
1
Bit
0
Bit Values
128
64
32
16
8
4
2
1
4th Octet of
IP Mask (249)
Bits 1 and 2 in the mask are “off”, and bits 0 and 3
- 7 are “on”, creating a value of 249 in the 4th octet.
Where a mask bit is “on”, the corresponding bit
setting in the address of a potentially authorized
station must match the IP Authorized Address
setting for that same bit. Where a mask bit is “off”
the corresponding bit setting in the address can be
either “on” or “off”. In this example, in order for a
station to be authorized to access the switch:
• The first three octets of the station’s IP address
must match the Authorized IP Address.
• Bit 0 and Bits 3 through 6 of the 4th octet in the
station’s address must be “on” (value = 1).
• Bit 7 of the 4th octet in the station’s address
must be “off” (value = 0).
• Bits 1 and 2 can be either “on” or “off”.
This means that stations with the IP address
13.28.227.
X
(where
X
is 121, 123, 125, or 127) are
authorized.
4th Octet of
IP Authorized
Address (125)
Summary of Contents for ProCurve 2510G Series
Page 1: ...Access Security Guide www procurve com ProCurve Series 2510G Switches Y 11 XX ...
Page 2: ......
Page 3: ...ProCurve Series 2510G Switches Access Security Guide June 2008 ...
Page 12: ...x ...
Page 26: ...1 10 Getting Started Need Only a Quick Start ...
Page 105: ...4 31 TACACS Authentication Configuring TACACS on the Switch ...
Page 106: ...4 32 TACACS Authentication Configuring TACACS on the Switch ...
Page 176: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 198: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Page 296: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Page 310: ...10 14 Using Authorized IP Managers Operating Notes ...
Page 318: ...8 Index ...
Page 319: ......