Security and authentication
11.6 Management Access Control List
SCALANCE XM-400/XR-500 Command Line Interface (CLI)
Configuration Manual, 06/2016, C79000-G8976-C252-11
863
The parameters have the following meaning:
Parameter
Description
Range of values / note
ip-address
Specifies the network or the IP address
for which the IP manager is authorized
Enter a valid IPv4 address or a
network.
subnet-mask
Subnet mask that restricts the authori-
zation
Enter a valid mask.
prefixlength
Decimal representation of the mask as
a number of "1" bits
0 ... 32
interface
Keyword for a an interface description -
interface-type
Type of interface
Enter a valid interface.
0/a-b,0/c,...
Module no. and port no. of the interface
vlan
Keyword for a VLAN connection
-
a,b or a-b or
a,b,c-d
Number of a VLAN or VLAN range
Enter a valid VLAN or VLAN
range.
cpu0
the Out of Band- interface is configured
as a management Interface
-
service
Specifies the services for which the
manager is authorized.
You can select several options.
•
snmp
•
telnet
•
http
•
https
•
ssh
For information on names of addresses and interfaces, refer to the section "Interface
identifiers and addresses (Page 42)".
The IP address 0.0.0.0 means "any manager".
If optional parameters are not specified when configuring, the manager is authorized for all
services.
Note
Configuration of the first entry
As long as the list of authorized managers is empty, access to the system is not restricted.
As soon as the list contains an entry and the "authorized-manager" command is executed,
access to the system is blocked for all others.
You should therefore configure the interface via which you access the system first because
your access is otherwise blocked.