HP 6125G HP 6125G & 6125G/XG Blade Switches Fundamentals Command Refer - Page 19

Login management commands, acl (user interface view)

Page 19 highlights

Login management commands acl (user interface view) Syntax To use a basic or advanced ACL: acl [ ipv6 ] acl-number { inbound | outbound } undo acl [ ipv6 ] acl-number { inbound | outbound } To use an Ethernet frame header ACL: acl acl-number inbound View undo acl acl-number inbound VTY user interface view Default level 2: System level Parameters ipv6: When this keyword is present, the command supports IPv6; otherwise, it supports IPv4. acl-number: Number of the ACL: • Basic ACL-2000 to 2999 • Advanced ACL-3000 to 3999 • Ethernet frame header ACL-4000 to 4999 inbound: Restricts Telnet or SSH connections established in the inbound direction through the VTY user interface. If the received packets for establishing a Telnet or SSH connection are permitted by an ACL rule, the connection is allowed to be established. When the device functions as a Telnet server or SSH server, this keyword is used to control access of Telnet clients or SSH clients. outbound: Restricts Telnet connections established in the outbound direction through the VTY user interface. If the packets sent for establishing a Telnet connection are permitted by an ACL rule, the connection is allowed to be established. When the device functions as a Telnet client, this keyword is used to define Telnet servers accessible to the client. Description Use acl to reference ACLs to control access to the VTY user interface. Use undo acl to cancel the ACL application. For more information about ACL, see ACL and QoS Configuration Guide. By default, access to the VTY user interface is not restricted. If no ACL is referenced in VTY user interface view, the VTY user interface has no access control over establishing a Telnet or SSH connection. If an ACL is referenced in VTY user interface view, the connection is permitted to be established only when packets for establishing a Telnet or SSH connection match a permit statement in the ACL. 12

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180

12
Login management commands
acl (user interface view)
Syntax
To use a basic or advanced ACL:
acl
[
ipv6
]
acl-number
{
inbound
|
outbound
}
undo acl
[
ipv6
]
acl-number
{
inbound
|
outbound
}
To use an Ethernet frame header ACL:
acl
acl-number
inbound
undo acl
acl-number
inbound
View
VTY user interface view
Default level
2: System level
Parameters
ipv6: When this keyword is present, the command supports IPv6; otherwise, it supports IPv4.
acl-number
: Number of the ACL:
Basic ACL
—2000 to 2999
Advanced ACL
—3000 to 3999
Ethernet frame header ACL
—4000 to 4999
inbound
: Restricts Telnet or SSH connections established in the inbound direction through the VTY user
interface. If the received packets for establishing a Telnet or SSH connection are permitted by an ACL rule,
the connection is allowed to be established. When the device functions as a Telnet server or SSH server,
this keyword is used to control access of Telnet clients or SSH clients.
outbound
: Restricts Telnet connections established in the outbound direction through the VTY user
interface. If the packets sent for establishing a Telnet connection are permitted by an ACL rule, the
connection is allowed to be established. When the device functions as a Telnet client, this keyword is
used to define Telnet servers accessible to the client.
Description
Use
acl
to reference ACLs to control access to the VTY user interface.
Use
undo acl
to cancel the ACL application. For more information about ACL, see
ACL and QoS
Configuration Guide
.
By default, access to the VTY user interface is not restricted.
If no ACL is referenced in VTY user interface view, the VTY user interface has no access control over
establishing a Telnet or SSH connection.
If an ACL is referenced in VTY user interface view, the connection is permitted to be established only
when packets for establishing a Telnet or SSH connection match a permit statement in the ACL.