10-12
Using Authorized IP Managers
Operating Notes
Additional Examples for Authorizing Multiple Stations
Operating Notes
■
Network Security Precautions:
You can enhance your network’s
security by keeping physical access to the switch restricted to autho-
rized personnel, using the password features built into the switch,
using the additional security features described in this manual, and
preventing unauthorized access to data on your management stations.
■
Modem and Direct Console Access:
Configuring authorized IP
managers does not protect against access to the switch through a
modem or direct Console (RS-232) port connection.
■
Duplicate IP Addresses:
If the IP address configured in an autho-
rized management station is also configured (or "spoofed") in another
station, the other station can gain management access to the switch
even though a duplicate IP address condition exists.
■
Web Proxy Servers:
If you use the web browser interface to access
the switch from an authorized IP manager station, it is recommended
that you avoid the use of a web proxy server in the path between the
station and the switch. This is because switch access through a web
proxy server requires that you first add the web proxy server to the
Authorized Manager IP list.
This reduces security by opening switch
access to anyone who uses the web proxy server
. The following two
options outline how to eliminate a web proxy server from the path
between a station and the switch:
Entries for Authorized
Manager List
Results
IP Mask
255 255 0
255
This combination specifies an authorized IP address of 10.33.
xxx
.1. It could be
applied, for example, to a subnetted network where each subnet is defined by the
third octet and includes a management station defined by the value of “1” in the
fourth octet of the station’s IP address.
Authorized
Manager IP
10
33
248 1
IP Mask
255 238 255 250
Allows 230, 231, 246, and 247 in the 2nd octet, and 194, 195, 198, 199 in the 4th octet.
Authorized
Manager IP
10
247 100 195
Summary of Contents for ProCurve 2510G Series
Page 1: ...Access Security Guide www procurve com ProCurve Series 2510G Switches Y 11 XX ...
Page 2: ......
Page 3: ...ProCurve Series 2510G Switches Access Security Guide June 2008 ...
Page 12: ...x ...
Page 26: ...1 10 Getting Started Need Only a Quick Start ...
Page 105: ...4 31 TACACS Authentication Configuring TACACS on the Switch ...
Page 106: ...4 32 TACACS Authentication Configuring TACACS on the Switch ...
Page 176: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 198: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Page 296: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Page 310: ...10 14 Using Authorized IP Managers Operating Notes ...
Page 318: ...8 Index ...
Page 319: ......