130
Fabric OS Administrator’s Guide
53-1001763-02
Telnet protocol
6
ATTENTION
The rule number assigned has to precede the default rule number for this protocol. For
example, in the defined policy, the Telnet rule number is 2, therefore to effectively block Telnet,
the rule number to assign must be 1.
If you choose not to use 1, you will need to delete the telnet rule number 2 after adding this
rule. Refer to
“Deleting a rule to an IP Filter policy”
on page 157 for more information on
deleting IP filter rules.
6. Save the new ipfilter policy by typing the ipfilter
--
save
command.
7. Verify the new policy is correct by typing the ipFilter
--
show command.
8. Activate the new ipfilter policy by typing the ipfilter
--
activate command.
switch:admin>
ipfilter --activate BlockTelnet
9. Verify the new policy is active (the default_ipv4 policy should be displayed as
defined
).
switch:admin>
ipfilter --show
Name:
BlockTelnet
, Type: ipv4, State: defined
Rule
Source IP
Protocol
Dest Port
Action
1
any tcp 23 deny
2
any tcp 22 permit
3
any tcp 22 permit
4
any tcp 897 permit
5
any tcp 898 permit
6
any tcp 111 permit
7
any tcp 80 permit
8
any tcp 443 permit
9
any udp 161 permit
10
any udp 111 permit
11
any udp 123 permit
12
any tcp 600
-
1023
permit
13
any udp 600
-
1023
permit
Name:
default_ipv4
, Type: ipv4, State: defined
Rule
Source IP
Protocol
Dest Port
Action
1
any tcp 22 permit
2
any tcp 23 permit
3
any tcp 897 permit
4
any tcp 898 permit
5
any tcp 111 permit
6
any tcp 80 permit
7
any tcp 443 permit
8
any udp 161 permit
9
any udp 111 permit
10
any udp 123 permit
11
any tcp 600
-
1023
permit
12
any udp 600
-
1023
permit
Unblocking Telnet
1. Connect to the switch through a serial port or SSH and log in as admin.
2. Type in the ipfilter
--
delete command.
Refer to
“Deleting a rule to an IP Filter policy”
on page 157 for more information on deleting IP
filter rules.
Содержание 53-1001763-02
Страница 1: ...53 1001763 02 13 September 2010 Fabric OS Administrator s Guide Supporting Fabric OS v6 4 0 ...
Страница 4: ...iv Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 24: ...xxiv Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 28: ...xxviii Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 32: ...xxxii Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 40: ...xl Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 42: ...2 Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 54: ...14 Fabric OS Administrator s Guide 53 1001763 02 High availability of daemon processes 1 ...
Страница 74: ...34 Fabric OS Administrator s Guide 53 1001763 02 Basic connections 2 ...
Страница 102: ...62 Fabric OS Administrator s Guide 53 1001763 02 Audit log configuration 3 ...
Страница 156: ...116 Fabric OS Administrator s Guide 53 1001763 02 The authentication model using RADIUS and LDAP 5 ...
Страница 214: ...174 Fabric OS Administrator s Guide 53 1001763 02 Management interface security 7 ...
Страница 228: ...188 Fabric OS Administrator s Guide 53 1001763 02 Brocade configuration form 8 ...
Страница 276: ...236 Fabric OS Administrator s Guide 53 1001763 02 Creating a logical fabric using XISLs 10 ...
Страница 404: ...364 Fabric OS Administrator s Guide 53 1001763 02 ...
Страница 440: ...400 Fabric OS Administrator s Guide 53 1001763 02 Performance data collection 17 ...
Страница 464: ...424 Fabric OS Administrator s Guide 53 1001763 02 Disabling bottleneck detection on a switch 18 ...
Страница 480: ...440 Fabric OS Administrator s Guide 53 1001763 02 F_Port masterless trunking 19 ...
Страница 494: ...454 Fabric OS Administrator s Guide 53 1001763 02 Buffer credit recovery 20 ...
Страница 560: ...520 Fabric OS Administrator s Guide 53 1001763 02 Port indexing on the Brocade DCX 4S backbone C ...
Страница 574: ...534 Fabric OS Administrator s Guide 53 1001763 02 Hexadecimal overview E ...