![CTC Union IFS-1604GSM Series Скачать руководство пользователя страница 47](http://html1.mh-extra.com/html/ctc-union/ifs-1604gsm-series/ifs-1604gsm-series_user-manual_2693578047.webp)
47
CHAPTER 3
CLI CONFIGURATION
for primary authentication it is recommended to configure secondary authentication as 'local'. This will enable the
management client to login via the local user database if none of the configured authentication servers are alive.
Example:
Set the Console client to use remote RADIUS server(s) for authentication.
Negation:
(config)# no aaa authentication login { console | telnet | ssh | http }
Show:
# show aaa
3.9.2 (config)# access management
Syntax:
(config)# access management <access_id> <access_vid> <start_addr> [ to <end_addr> ] { [ web ] [ snmp ]
[ telnet ] | all }
Explanation:
Create an access management rule.
Parameters:
<access_id: 1-16>: Specify an ID for this access management entry.
<access_vid>: Indicates the VLAN ID for the access management entry.
<start_addr> [ to <end_addr> ]: Indicate the starting and ending IP address for the access management entry.
{ [ web ] [ snmp ] [ telnet ] | all }: Specify matched hosts can access the switch from which interface.
Example:
Allow IP 192.168.0.1 to 192.168.0.10 to access the device via Web, SNMP and Telnet.
Negation:
(config)# no access management
(config)# no access management <access_id>
Show:
# show access management [ statistics | <access_id_list> ]
Clear:
# clear access management statistics
3.9.3 (config)# access-list
3.9.3.1 (config)# access-list ace
Syntax:
(config)# access-list ace <AceId : 1-256> [ action {deny | filter | permit}] [ dmac-type {any| broadcast |
multicast | unicast } ] [frame-type {any| arp|etype|ipv4|ipv4-icmp|ipv4-tcp|ipv4-udp|ipv6|ipv6-icmp|ipv6-tcp|ipv6-
udp} ] [ingress {any | interface <PORT_TYPE> }] [logging] [mirror] [next { <AceId : 1-256>|last}] [policy <PolicyId : 0-
255>] [rate-limiter {<RateLimiterId : 1-16>|disable}] [redirect {disable| interface <PORT_TYPE>}] [shutdown] [tag
{any|tagged|untagged}] [tag-priority {0-1| 0-3| 2-3| 4-5| 4-7| 6-7| <TagPriority : 0-7>|any}] [vid { <Vid : 1-
# config t
(config)# access management 1 1 192.168.0.1 to 192.168.0.10 all
# config t
(config)# aaa authentication login console radius
Содержание IFS-1604GSM Series
Страница 385: ......