44
Chapter 2 Getting started
NN46110-500
Restricting source IPs access to management
You are able to filter management access of source IP addresses. Access Lists
(ACLs) restrict connection of designated source IPs for management purposes
over HTTP, FTP, TELNET and SNMP. Management traffic is intercepted and if
the destination is System and the packet is for one of the four services above, the
source IP address is matched against the ACL that is set for the particular service.
If no ACL is defined for HTTP, for example, then http traffic is permited for any
IP address that comes as a source address in the packet.
The IP address of a source client is logged in the syslog output whether the logon
connection attempt is successful or not.
Configuring ACL through the CLI:
Use the following commands to configure ACL in CLI:
To set an ACL for HTTP, enter the following NNCLI command:
CES(config)#
http access-list
<the_name_of_an_acl>
To remove an ACL for HTTP, enter the following command:
CES(config)
#no http access-list
To set an ACL for FTP, enter the following NNCLI command:
CES(config)
#ftp-server access-list
<the_name_of_an_acl>
To remove an ACL for FTP, enter the following command:
CES(config)#
no ftp-server access-list
To set an ACL for SNMP, enter the following NNCLI command:
CES(config)
#snmp-server access-list
<the_name_of_an_acl>
To remove an ACL for SNMP, enter the following command:
CES(config)
#no snmp-server access-list
Содержание Contivity 1050
Страница 10: ...10 Contents NN46110 500 ...
Страница 14: ...14 Tables NN46110 500 ...
Страница 22: ...22 Preface NN46110 500 ...
Страница 58: ...58 Chapter 2 Getting started NN46110 500 ...
Страница 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Страница 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Страница 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Страница 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Страница 164: ...164 Branch office quick start template NN46110 500 ...
Страница 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...