ESR series routers
17
IP address Interface Type
------------------- ------------ -------
192.168.11.5/25 gi1/0/4
DHCP
6.5.
Router remote configuration
The default configuration has a remote access to the router via Telnet or SSH protocols from the
«trusted»
zones. To permit remote access from the other zone (for example, WAN) you need to create
corresponding rules in Firewall.
Rules are created for couple zones when you configure the access to the router:
source-zone
– zone for realizing of the remote access;
self
– zone where router control interface is located.
Use the next command to create feeding rule:
esr-1000#
configure
esr-1000(config)#
security zone-pair <source-zone> self
esr-1000(config-zone-pair)#
rule <number>
esr-1000(config-zone-rule)#
action permit
esr-1000(config-zone-rule)#
match protocol tcp
esr-1000(config-zone-rule)#
match source-address <network object-group>
esr-1000(config-zone-rule)#
match destination-address <network object-group>
esr-1000(config-zone-rule)#
match source-port any
esr-1000(config-zone-rule)#
match destination-port <service object-group>
esr-1000(config-zone-rule)#
enable
esr-1000(config-zone-rule)#
exit
esr-1000(config-zone-pair)#
exit
Command examples to permit connection to the router with IP-address
40.13.1.22
by SSH-protocol
for user from
«untrusted»
zone with IP-addresses:
132.16.0.5-132.16.0.10
esr-1000#
configure
esr-1000(config)#
object-group network clients
esr-1000(config-object-group-network)#
ip address-range 132.16.0.5-132.16.0.10
esr-1000(config-object-group-network)#
exit
esr-1000(config)#
object-group network gateway
esr-1000(config-object-group-network)#
ip address-range 40.13.1.22
esr-1000(config-object-group-network)#
exit
esr-1000(config)#
object-group service ssh
esr-1000(config-object-group-service)#
port-range 22
esr-1000(config-object-group-service)#
exit
esr-1000(config)#
security zone-pair untrusted self
esr-1000(config-zone-pair)#
rule 10
esr-1000(config-zone-rule)#
action permit
esr-1000(config-zone-rule)#
match protocol tcp
esr-1000(config-zone-rule)#
match source-address clients
esr-1000(config-zone-rule)#
match destination-address gateway
esr-1000(config-zone-rule)#
match source-port any
esr-1000(config-zone-rule)#
match destination-port ssh
esr-1000(config-zone-rule)#
enable
esr-1000(config-zone-rule)#
exit
esr-1000(config-zone-pair)#
exit