
Management ACL Commands
1379
69
Management ACL Commands
In order to ensure the security of the switch management features, the
administrator may elect to configure a management access control list. The
Management Access Control and Administration List (ACAL) component is
used to ensure that only known and trusted devices are allowed to remotely
manage the switch via TCP/IP. Management ACLs are only configurable on
IP (in-band) interfaces, not on the service port.
When a Management ACAL is enabled, incoming TCP packets initiating a
connection (TCP SYN) and all UDP packets will be filtered based on their
source IP address and destination port. Additionally, other attributes such as
incoming port (or port-channel) and VLAN ID can be used to determine if
the traffic should be allowed to the management interface. When the
component is disabled, incoming TCP/UDP packets are not filtered and are
processed normally.
There is also an option to restrict all the above packets from the network
interface. This is done by specifying “console only” in the MACAL
component. If this is enabled, the systems management interface is only
accessible via the serial port. All TCP SYN packets and UDP packets are
dropped except UDP packets sent to the DHCP Server or DHCP Client
ports.
Commands in this Chapter
This chapter explains the following commands:
deny (management)
permit (management)
management access-class
show management access-class
management access-list
show management access-list
2CSPC4.XModular-SWUM200.book Page 1379 Thursday, March 10, 2011 11:18 AM
Содержание PowerEdge M420
Страница 161: ...Command Groups 161 ...
Страница 162: ...162 Command Groups ...
Страница 216: ...216 Layer 2 Commands ...
Страница 290: ...290 Auto VoIP Commands ...
Страница 310: ...310 Data Center Bridging Commands ...
Страница 316: ...316 DHCP Layer 2 Relay Commands Example console config dhcp l2relay vlan 10 340 345 ...
Страница 324: ...324 DHCP Management Interface Commands ...
Страница 340: ...340 DHCP Snooping Commands ...
Страница 354: ...354 Dynamic ARP Inspection Commands ...
Страница 405: ...Ethernet Configuration Commands 405 Name test ...
Страница 406: ...406 Ethernet Configuration Commands ...
Страница 426: ...426 Ethernet CFM Commands ...
Страница 486: ...486 IPv6 Access List Commands ...
Страница 497: ...IPv6 MLD Snooping Commands 497 Vlan Ipv6 Address Ports ...
Страница 498: ...498 IPv6 MLD Snooping Commands ...
Страница 512: ...512 IP Source Guard Commands ...
Страница 524: ...524 iSCSI Optimization Commands ...
Страница 532: ...532 Link Dependency Commands ...
Страница 572: ...572 Port Aggregator Commands ...
Страница 596: ...596 Port Monitor Commands Session ID Admin Mode Probe Port Mirrored Port Type 1 Enable 1 0 10 1 0 8 Rx Tx ...
Страница 756: ...756 VLAN Commands ...
Страница 762: ...762 Voice VLAN Commands ...
Страница 796: ...796 802 1x Commands ...
Страница 798: ...798 Layer 3 Commands ...
Страница 842: ...842 DHCP Server and Relay Agent Commands ...
Страница 868: ...868 DVMRP Commands ...
Страница 888: ...888 IGMP Commands ...
Страница 896: ...896 IGMP Proxy Commands ...
Страница 938: ...938 IP Routing Commands ...
Страница 1012: ...1012 IPv6 Routing Commands ...
Страница 1016: ...1016 Loopback Interface Commands ...
Страница 1048: ...1048 Multicast Commands ...
Страница 1064: ...1064 IPv6 Multicast Commands RP Address 3001 1 origin BSR ...
Страница 1142: ...1142 OSPF Commands ...
Страница 1202: ...1202 OSPFv3 Commands ...
Страница 1212: ...1212 Router Discovery Protocol Commands ...
Страница 1228: ...1228 Routing Information Protocol Commands ...
Страница 1234: ...1234 Tunnel Interface Commands console config interface tunnel 1 console config if tunnel1 tunnel source vlan 11 ...
Страница 1260: ...1260 Virtual Router Redundancy Protocol Commands ...
Страница 1262: ...1260 Utility Commands ...
Страница 1272: ...1270 Auto Install Commands ...
Страница 1306: ...1304 Captive Portal Commands ...
Страница 1316: ...1314 CLI Macro Commands ...
Страница 1334: ...1332 Clock Commands ...
Страница 1340: ...1338 Command Line Configuration Scripting Commands ...
Страница 1362: ...1360 Configuration and Image File Commands ...
Страница 1363: ...Configuration and Image File Commands 1361 ...
Страница 1364: ...1362 Configuration and Image File Commands ...
Страница 1412: ...1408 Password Management Commands ...
Страница 1436: ...1432 RMON Commands ...
Страница 1476: ...1472 Sflow Commands ...
Страница 1536: ...1532 Syslog Commands ...
Страница 1602: ...1598 Telnet Server Commands ...
Страница 1604: ...1600 Terminal Length Commands ...
Страница 1618: ...1614 User Interface Commands ...
Страница 1638: ...1634 Web Server Commands ...
Страница 1680: ...1676 Appendix A List of Commands ...
Страница 1681: ......
Страница 1682: ...www dell com support dell com Printed in the U S A ...