data:image/s3,"s3://crabby-images/5a5c0/5a5c02aadc4dfc2a9f4572de5ac5a2b77e4117e7" alt="Symmetricom TimeProvider 1000 User Manual Download Page 78"
78
TimeCreator 1000 User’s Guide
097-93100-01 Revision C – February, 2010
Chapter 5 Provisioning
Managing the IP Address Whitelist
Managing the IP Address Whitelist
The whitelist feature in TimeCreator allows the user to filter IP access addresses to
prevent malicious attacks. In the default condition, all IP addresses are allowed
access. Once the first IP address has been added to the whitelist, any future IP
sessions will only be accepted if they originate from IP addresses from the whitelist.
This feature is useful when the management port is connected to a public network
rather than a private network.
The whitelist must be committed before any changes to the whitelist will be
implemented.
Add an IP Address to the Whitelist
Use the dot-decimal notation format xxx.xxx.xxx.xxx to enter the IP address
parameter.
1. Login at the Admin level (see
2. To view the current list of IP addresses on the whitelist, type
show whitelist
and press
Enter
.
3. To add a specific IP address to the whitelist, type
set whitelist add <ip
address>
and press
Enter
. (For example,
set whitelist add
192.168.5.10
).
4. To add IP addresses using a subnet mask, type
set whitelist add <ip
address>/<ip mask>
and press
Enter
. The mask indicates which parts of the IP
address are significant
it is specified as a prefix number which is the number of
1s from the MSB with the remaining bits set to 0. A mask of 255.255.255.0 is set
with the value 24. (For example,
set whitelist add 192.168.5.0/24
) The
default value is 32, or 255.255.255.255, to match the full 32-bit IP address. .
5. Type
set whitelist commit
and press
Enter.
Note:
Symmetricom recommends that the IP address of the
administrator station always be added to the whitelist first. This will
prevent an accidental lockout of the administrator via Telnet/SSH.
Note:
If the whitelist function is being use for a TimeCreator 1000 with
the TOD-source of NTP, the local host address (
127.0.0.1)
should be
added to the whitelist with the command “
set whitelist add
127.0.0.1”
.