Configuring Security
Defining Access Profiles
Cisco 500 Series Stackable Managed Switch Administration Guide
308
18
•
Interface
—Which ports, LAGs, or VLANs are permitted to access or are
denied access to the web-based switch configuration utility.
•
Source IP Address
—IP addresses or subnets. Access to management
methods might differ among user groups. For example, one user group
might be able to access the switch module only by using an HTTPS
session, while another user group might be able to access the switch
module by using both HTTPS and Telnet sessions.
Active Access Profile
The
Access Profiles
page displays the access profiles that are defined and
enables selecting one access profile to be the active one.
When a user attempts to access the switch through an access method, the switch
looks to see if the active access profile explicitly permits management access to
the switch through this method. If no match is found, access is denied.
When an attempt to access the switch is in violation of the active access profile,
the switch generates a SYSLOG message to alert the system administrator of the
attempt.
If a console-only access profile has been activated, the only way to deactivate it is
through a direct connection from the management station to the physical console
port on the switch.
For more information see Defining Profile Rules.
Use the
Access Profiles
page to create an access profile and to add its first rule. If
the access profile only contains a single rule, you are finished. To add additional
rules to the profile, use the Profile Rules page.
STEP 1
Click
Security
>
Mgmt Access Method
>
Access Profiles
. The
Access Profiles
page is displayed.
This page displays all of the access profiles, active and inactive.
STEP 2
To change the active access profile, select a profile from the
Active Access
Profile
drop down menu and click
Apply
. This makes the chosen profile the active
access profile.
NOTE
A caution message is displayed if you selected Console Only. If you
continue, you are immediately disconnected from the web-based switch
configuration utility and can access the switch only through the console port.
This only applies to device types that offer a console port.