Cisco CISCO1401 Software Guide - Page 76

Creating an Access Group and Assigning a Basic IP Access List, serve, serve-only, query-only

Page 76 highlights

Managing the System Time and Date Chapter 5 Administering the Bridge Creating an Access Group and Assigning a Basic IP Access List Beginning in privileged EXEC mode, follow these steps to control access to NTP services by using access lists: Step 1 Step 2 Command configure terminal ntp access-group {query-only | serve-only | serve | peer} access-list-number Step 3 access-list access-list-number permit source [source-wildcard] Step 4 Step 5 Step 6 end show running-config copy running-config startup-config Purpose Enter global configuration mode. Create an access group, and apply a basic IP access list. The keywords have these meanings: • query-only-Allows only NTP control queries. • serve-only-Allows only time requests. • serve-Allows time requests and NTP control queries, but does not allow the bridge to synchronize to the remote device. • peer-Allows time requests and NTP control queries and allows the bridge to synchronize to the remote device. For access-list-number, enter a standard IP access list number from 1 to 99. Create the access list. • For access-list-number, enter the number specified in Step 2. • Enter the permit keyword to permit access if the conditions are matched. • For source, enter the IP address of the device that is permitted access to the bridge. • (Optional) For source-wildcard, enter the wildcard bits to be applied to the source. Note When creating an access list, remember that, by default, the end of the access list contains an implicit deny statement for everything if it did not find a match before reaching the end. Return to privileged EXEC mode. Verify your entries. (Optional) Save your entries in the configuration file. The access group keywords are scanned in this order, from least restrictive to most restrictive: 1. peer-Allows time requests and NTP control queries and allows the bridge to synchronize itself to a device whose address passes the access list criteria. 2. serve-Allows time requests and NTP control queries, but does not allow the bridge to synchronize itself to a device whose address passes the access list criteria. 3. serve-only-Allows only time requests from a device whose address passes the access list criteria. 4. query-only-Allows only NTP control queries from a device whose address passes the access list criteria. 5-24 Cisco Aironet 1400 Series Wireless Bridges Software Configuration Guide OL-4059-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286

5-24
Cisco Aironet 1400 Series Wireless Bridges Software Configuration Guide
OL-4059-01
Chapter 5
Administering the Bridge
Managing the System Time and Date
Creating an Access Group and Assigning a Basic IP Access List
Beginning in privileged EXEC mode, follow these steps to control access to NTP services by using
access lists:
The access group keywords are scanned in this order, from least restrictive to most restrictive:
1.
peer
—Allows time requests and NTP control queries and allows the bridge to synchronize itself to
a device whose address passes the access list criteria.
2.
serve
—Allows time requests and NTP control queries, but does not allow the bridge to synchronize
itself to a device whose address passes the access list criteria.
3.
serve-only
—Allows only time requests from a device whose address passes the access list criteria.
4.
query-only
—Allows only NTP control queries from a device whose address passes the access list
criteria.
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
ntp access-group
{
query-only
|
serve-onl
y |
serve
|
peer
}
access-list-number
Create an access group, and apply a basic IP access list.
The keywords have these meanings:
query-only
—Allows only NTP control queries.
serve-only
—Allows only time requests.
serve
—Allows time requests and NTP control queries, but does not
allow the bridge to synchronize to the remote device.
peer
—Allows time requests and NTP control queries and allows the
bridge to synchronize to the remote device.
For
access-list-number
, enter a standard IP access list number from 1
to 99.
Step 3
access-list
access-list-number
permit
source
[
source-wildcard
]
Create the access list.
For
access-list-number
, enter the number specified in Step 2.
Enter the
permit
keyword to permit access if the conditions are
matched.
For
source
, enter the IP address of the device that is permitted access
to the bridge.
(Optional) For
source-wildcard
, enter the wildcard bits to be applied
to the source.
Note
When creating an access list, remember that, by default, the end
of the access list contains an implicit deny statement for
everything if it did not find a match before reaching the end.
Step 4
end
Return to privileged EXEC mode.
Step 5
show running-config
Verify your entries.
Step 6
copy running-config startup-config
(Optional) Save your entries in the configuration file.