48-5
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter48 Configuring Device Access Settings on Firewall Devices
Configuring Management Access
Configuring Management Access
Use the Management Access page to enable or disable access on a high-security interface so you can
perform management functions on the device. You can enable this feature on an internal interface to
allow management functions to be performed on the interface over an IPsec VPN tunnel. You can enable
the Management Access feature on only one interface at a time.
Navigation Path
(Device view) Select Platform > Device Admin > Device Access > Management Access from the
Device Policy selector.
(Policy view) Select PIX/ASA/FWSM Platform > Device Admin > Device Access > Management
Access from the Policy Type selector. Select an existing policy from the Shared Policy selector, or
create a new one.
Enabling and Disabling Management Access
In the Management Access Interface field, enter the name of the device interface that is to permit
management access connections. You can click Select to select the interface from a list of interface
objects.
You can enable the Management Access feature on only one interface at a time.
Clear the Management Access Interface field to disable management access.
Configuring Secure Shell Access
Use the Secure Shell page to configure rules that permit administrative access to a security device using
the SSH protocol. The rules restrict SSH access to a specific IP address and netmask. Any SSH
connection attempts that comply with these rules must then be authenticated by an AAA server or Telnet
password.
Navigation Path
(Device v iew) Select Platform > Device Admin > Device Access > Secure Shell from the Device
Policy selector.
(Policy view) Select PIX/ASA/FWSM Platform > Device Admin > Device Access > Secure Shell
from the Policy Type selector. Select an existing policy from the Shared Policy selector, or create a
new one.
Network Enter a host name or IP address, or Select a Networks/Hosts object, to
define the specified ICMP message source.
Table48-4 Add and ICMP Dialog Boxes (Continued)
Element Description