Cisco CRS-1 - Carrier Routing System Router Configuration Manual page 190

Ios xr system security configuration guide
Hide thumbs Also See for CRS-1 - Carrier Routing System Router:
Table of Contents

Advertisement

How to Configure a Device for Management Plane Protection
Management Plane Protection Feature
The MPP protection feature, as well as all the management protocols under MPP, are disabled by default.
When you configure an interface as either out-of-band or inband, it automatically enables MPP.
Consequently, this enablement extends to all the protocols under MPP.
If MPP is disabled and a protocol is activated, all interfaces can pass traffic.
When MPP is enabled with an activated protocol, the only default management interfaces allowing
management traffic are the route processor (RP) and standby route processor (SRP) Ethernet interfaces.
You must manually configure any other interface for which you want to enable MPP as a management
interface, using the MPP CLI that follows. Afterwards, only the default management interfaces and those
you have previously configured as MPP interfaces will accept network management packets destined for
the device. All other interfaces drop such packets.
Note
Logical interfaces (or any other interfaces not present on the data plane) filter packets based on the
ingress physical interface.
After configuration, you can modify or delete a management interface.
Following are the management protocols that the MPP feature supports. These management protocols
are also the only protocols affected when MPP is enabled.
Benefits of the Management Plane Protection Feature
Implementing the MPP feature provides the following benefits:
How to Configure a Device for Management Plane Protection
This section contains the following tasks:
Cisco IOS XR System Security Configuration Guide for the Cisco CRS-1 Router
SC-184
SSH, v1 and v2
SNMP, all versions
Telnet
TFTP
HTTP
HTTPS
Greater access control for managing a device than allowing management protocols on all interfaces.
Improved performance for data packets on non-management interfaces.
Support for network scalability.
Simplifies the task of using per-interface access control lists (ACLs) to restrict management access
to the device.
Fewer ACLs are needed to restrict access to the device.
Prevention of packet floods on switching and routing interfaces from reaching the CPU.
Configuring a Device for Management Plane Protection for an Inband Interface, page SC-185
Implementing Management Plane Protection on Cisco IOS XR Software
OL-20382-01

Advertisement

Table of Contents
loading

Table of Contents