37-2
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 37 Configuring the IP Permit List
IP Permit List Default Configuration
If you do not specify the mask for an IP permit list entry, or if you enter a host name instead of an IP
address, the mask has an implicit value of all bits that are set to one (255.255.255.255 or 0xffffffff),
which matches only the IP address of that host.
If you do not specify SNMP or Telnet for the type of permit list for the IP address, the IP address is added
to both the SNMP and Telnet permit lists.
You can specify the same IP address in more than one entry in the permit list if the masks are different.
The mask is applied to the address before it is stored in NVRAM, so that the entries that have the same
effect but different addresses are not stored. When you add such an address to the IP permit list, the
system displays the address after the mask is applied.
IP Permit List Default Configuration
Table 37-1
shows the default IP permit list configuration.
Configuring the IP Permit List on the Switch
These sections describe how to configure the IP permit list:
•
Adding IP Addresses to the IP Permit List, page 37-2
•
Enabling the IP Permit List, page 37-3
•
Disabling the IP Permit List, page 37-4
•
Clearing an IP Permit List Entry, page 37-5
Adding IP Addresses to the IP Permit List
You can add an IP address to the SNMP permit list, the Telnet permit list, or both lists.
To add IP addresses to the IP permit list, perform this task in privileged mode:
Table 37-1
IP Permit List Default Configuration
Feature
Default Value
IP permit list enable state
Disabled
Permit list entries
None configured
IP syslog message severity level
2
SNMP IP permit trap (ippermit)
Disabled
Task
Command
Step 1
Specify the IP addresses to add to the IP permit
list.
set ip permit
ip_address
[
mask
] [
telnet
|
snmp
|
ssh
]
Step 2
Verify the IP permit list configuration.
show ip permit