![Alcatel-Lucent 7950 SR Скачать руководство пользователя страница 65](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148065.webp)
Security
7950 SR OS System Management Guide
Page 65
Security Configuration Procedures
•
Configuring Management Access Filters on page 65
•
Configuring CPM Filters Policy on page 67
•
Configuring Password Management Parameters on page 68
•
Configuring Profiles on page 71
•
•
Copying and Overwriting Users and Profiles on page 74
•
Configuring Management Access Filters
Creating and implementing management access filters is optional. Management access filters are
software-based filters that control all traffic going in to the , including all routing protocols. They
apply to packets from all ports. The filters can be used to restrict management of the router by
other nodes outside either specific (sub)networks or through designated ports. By default, there are
no filters associated with security options. The management access filter and entries must be
explicitly created on each router. These filters also apply to the management Ethernet port.
The OS implementation exits the filter when the first match is found and execute the actions
according to the specified action. For this reason, entries must be sequenced correctly from most
to least explicit. When both
mac-filter
and
ip-filter/ipv6-filter
are to be applied to a given traffic,
mac-filter
is applied first.
An entry may not have any match criteria defined (in which case, everything matches) but must
have at least an action keyword specified to be considered active . Entries without the action
keyword are considered incomplete and will be rendered inactive. Management Access Filter
must have at least one active entry defined for the filter to be active.
The following is an example of a management access filter configuration that accepts packets
matching the criteria specified in IP, IPv6 and MAC entries. Non-matching packets are denied for
IPv4 filter and permitted for IPv6 and MAC filters.
*A:Dut-C>config>system>security>mgmt-access-filter# info
----------------------------------------------
ip-filter
default-action deny
entry 10
description "Accept SSH from mgmnt subnet"
src-ip 192.168.5.0/26
protocol tcp
dst-port 22 65535
action permit
Содержание 7950 SR
Страница 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Страница 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Страница 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Страница 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Страница 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Страница 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Страница 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Страница 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Страница 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Страница 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Страница 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Страница 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Страница 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Страница 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Страница 460: ...Standards and Protocols Page 460 Standards and Protocols...