15-11
Using Authorized IP Managers
Building IP Masks
Building IP Masks
The IP Mask parameter controls how the switch uses an Authorized Manager
IP value to recognize the IP addresses of authorized manager stations on your
network.
Configuring One Station Per Authorized Manager IP
Entry
This is the easiest way to apply a mask. If you have ten or fewer management
and/or operator stations, you can configure them by adding the address of
each to the Authorized Manager IP list with
255.255.255.255
for the correspond-
ing mask. For example, as shown in figure 15-3, if you configure an IP address
of
10.28.227.125
with an IP mask of
255.255.255.255
, only a station having an IP
address of
10.28.227.125
has management access to the switch.
Figure 15-6. Analysis of IP Mask for Single-Station Entries
Configuring Multiple Stations Per Authorized Manager
IP Entry
The mask determines whether the IP address of a station on the network meets
the criteria you specify. That is, for a given Authorized Manager entry, the
switch applies the IP mask to the IP address you specify to determine a range
of authorized IP addresses for management access. As described above, that
range can be as small as one IP address (if
255
is set for all octets in the mask),
or can include multiple IP addresses (if one or more octets in the mask are set
to less than
255
).
If a bit in an octet of the mask is “on” (set to 1), then the corresponding bit in
the IP address of a potentially authorized station must match the same bit in
the IP address you entered in the Authorized Manager IP list. Conversely, if a
bit in an octet of the mask is “off” (set to 0), then the corresponding bit in the
IP address of a potentially authorized station on the network does not have to
match its counterpart in the IP address you entered in the Authorized Manager
IP list. Thus, in the example shown above, a “255” in an IP Mask octet (
all
bits
1st
Octet
2nd
Octet
3rd
Octet
4th
Octet
Manager-Level or Operator-Level Device Access
IP Mask
255
255
255
255
The “255” in each octet of the mask specifies that only the exact value in
that octet of the corresponding IP address is allowed. This mask allows
management access only to a station having an IP address of 10.33.248.5.
Authorized
Manager IP
10
28
227
125
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......