Security Configuration Procedures; Configuring Management Access Filters - Alcatel-Lucent 7450 System Management Manual

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

Configuring Management Access Filters

Security Configuration Procedures

Configuring Management Access Filters
Creating and implementing management access filters is optional. Management access filters are
software-based filters that control all traffic going in to the CPM, including all routing protocols.
They apply to packets from all ports. The filters can be used to restrict management of the router
by other nodes outside either specific (sub)networks or through designated ports. By default, there
are no filters associated with security options. The management access filter and entries must be
explicitly created on each router. These filters also apply to the management Ethernet port.
The OS implementation exits the filter when the first match is found and execute the actions
according to the specified action. For this reason, entries must be sequenced correctly from most to
least explicit. When both mac-filter and ip-filter/ipv6-filter are to be applied to a given traffic,
mac-filter is applied first.
An entry may not have any match criteria defined (in which case, everything matches) but must
have at least keyword CPM to be considered complete. Entries without the action keyword are
considered incomplete and will be rendered inactive. Management Access Filter must have at least
one active entry defined for the filter to be active.
Use the following CLI commands to configure a management access filter. This example only
accepts packets matching the criteria specified in entries 1 and 2. Non-matching packets are
denied.
CLI Syntax: config>system
Page 72
Configuring Management Access Filters on page 72
Configuring IP CPM Filters Policy on page 75
Configuring MAC CPM Filters on page 76
Configuring CPM Queues on page 77
Configuring Profiles on page 80
Configuring Users on page 81
Copying and Overwriting Users and Profiles on page 83
Enabling SSH on page 95
security
management-access-filter
[no] ip-filter
default-action {permit|deny|deny-host-unreachable}
renum old-entry-number new-entry-number
[no] shutdown
7450 ESS System Mangement Guide

Advertisement

Table of Contents
loading

Table of Contents