User’s Manual of WGSD-1022/WGSD-8000

5.13.2 permit (management)

The permit management access-list configuration command defines a permit rule.

Syntax

permit [ethernet interface-numbervlan vlan-idport-channel number out-of-band-eth oob-interface] [service service] permit ip-source ip-address[mask mask prefix-length] [ethernet interface-numbervlan vlan-idport-channel number out-of-band-eth oob-interface] [service service]

ƒethernet interface-number— A valid Ethernet port number.

ƒvlan vlan-id— A valid VLAN number.

ƒport-channelnumber — A valid port channel number.

ƒip-address— Source IP address.(Range: Valid IP Address)

ƒmask mask — Specifies the network mask of the source IP address. (Range: Valid subnet mask)

ƒmask prefix-length— Specifies the number of bits that comprise the source IP address prefix. The prefix length must be preceded by a forward slash (/). (Range: 0 - 32)

ƒservice service — Indicates service type. Can be one of the following: telnet, ssh, http, https or snmp.

ƒout-of-band-ethoob-interface— Out of band ethernet port number.

Default Configuration

This command has no default configuration.

Command Mode

Management Access-list Configuration mode

User Guidelines

Rules with Ethernet, VLAN and port-channel parameters are valid only if an IP address is defined on the appropriate interface.The system supports up to 256 management access rules.

Example

The following example shows how all ports are permitted in the access-list called "mlist".

Console (config)# management access-listmlist

Console (config-macl)# permit

5.13.3 deny (management)

The deny management access-list configuration command defines a deny rule.

Syntax

deny [ethernet interface-numbervlan vlan-idport-channel number ] [service service]

- 244 –