Cisco SGE2000 Configuration Guide - Page 80

Step 9, Step 10

Page 80 highlights

Initial System Configuration Chapter 5 Connecting the Management Interfaces and Performing Initial System Configuration Step 9 Step 10 • When all ACLs have been created, press Enter. Would you like to configure another list? [no]: You are now prompted to assign the desired ACLs to restrict IP and Telnet access. Restrict IP access to the SCE 2000 by assigning the appropriate ACL. Type the number of the ACL to be assigned to IP access and press Enter. To accept the default ACL, press Enter. Enter IP access-class [0]: Restrict Telnet access to the SCE 2000 by assigning the appropriate ACL. Type the number of the ACL to be assigned to the Telnet interface and press Enter. To accept the default ACL, press Enter. Enter Telnet access-class [0]: 2 EXAMPLE 1: This example illustrates a common access control scenario. Let us assume the following: • We want to permit every station to access the SCE platform on the management port (e.g. ping, SNMP polling etc.). • We want to restrict Telnet access to only a few permitted stations. We therefore need to create two access control lists: : • For general IP access - permit access to all IP addresses. • For Telnet - permit access to the specified IP address, and deny to all others. ACL #1 = permit any IP address. Assign to IP access. ACL #2 = permit access to 10.1.1.0, 10.10.10.1, deny to all others. Assign to Telnet access. Would you like to enter the Access lists configuration menu? [no]: yWould you like to create new Access lists or modify existing lists? [no]: yEnter ACL number: 1Does this entry permit access? [yes]: Enter IP address or the word 'any' to denote any IP address: anyThis entry matches every IP address, no use in adding more entries to this list. Would you like to configure another list? [no]: yEnter ACL number: 2Does this entry permit access? [yes]: Enter IP address or the word 'any' to denote any IP address: 10.1.1.0 Enter wildcard bits: 0.0.0.0Would you like to add another entry to this list? [no]:yDoes this entry permit access? [yes]: Enter IP address or the word 'any' to denote any IP address: 10.10.10.1 Enter wildcard bits: 0.0.0.0Would you like to add another entry to this list? [no]:yDoes this entry permit access? [yes]:nEnter IP address or the word 'any' to denote any IP address: anyThis entry matches every IP address, no use in adding more entries to this list. Would you like to configure another list? [no]: Enter IP access-class [0]: 1Enter Telnet access-class [0]: 2 EXAMPLE 2: This example skips the first section of the dialog (creating/modifying), and proceeds directly to assign existing ACLs. Would you like to enter the Access lists configuration menu? [no]: yWould you like to create new Access lists or modify existing lists? [no]: Enter IP access-class [0]: 10Enter Telnet access-class [0]: 22 5-16 Cisco SCE 2000 4xGBE Installation and Configuration Guide OL-7824-06

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142

5-16
Cisco SCE 2000 4xGBE Installation and Configuration Guide
OL-7824-06
Chapter 5
Connecting the Management Interfaces and Performing Initial System Configuration
Initial System Configuration
When all ACLs have been created, press Enter.
Would you like to configure another list? [no]:
You are now prompted to assign the desired ACLs to restrict IP and Telnet access.
Step 9
Restrict IP access to the
SCE 2000
by assigning the appropriate ACL.
Type the number of the ACL to be assigned to IP access and press Enter.
To accept the default ACL, press Enter.
Enter IP access-class [0]:
Step 10
Restrict Telnet access to the
SCE 2000
by assigning the appropriate ACL.
Type the number of the ACL to be assigned to the Telnet interface and press Enter.
To accept the default ACL, press Enter.
Enter Telnet access-class [0]:
2
EXAMPLE 1:
This example illustrates a common access control scenario. Let us assume the following:
We want to permit every station to access the SCE platform on the management port (e.g. ping,
SNMP polling etc.).
We want to restrict Telnet access to only a few permitted stations.
We therefore need to create two access control lists: :
For general IP access — permit access to all IP addresses.
For Telnet — permit access to the specified IP address, and deny to all others.
ACL #1 = permit any IP address. Assign to IP access.
ACL #2 = permit access to 10.1.1.0, 10.10.10.1, deny to all others. Assign to Telnet access.
Would you like to enter the Access lists configuration menu? [no]:
y
Would you like to
create new Access lists or modify existing lists? [no]:
y
Enter ACL number:
1
Does this
entry permit access? [yes]:
Enter IP address or the word ‘any’ to denote any IP address:
any
This entry matches every
IP address, no use in adding more entries to this list.
Would you like to configure another list? [no]:
y
Enter ACL number:
2
Does this entry permit
access? [yes]:
Enter IP address or the word ‘any’ to denote any IP address: 10.1.1.0
Enter wildcard bits:
0.0.0.0
Would you like to add another entry to this list? [no]:
y
Does
this entry permit access? [yes]:
Enter IP address or the word ‘any’ to denote any IP address: 10.10.10.1
Enter wildcard bits:
0.0.0.0
Would you like to add another entry to this list? [no]:
y
Does
this entry permit access? [yes]:
n
Enter IP address or the word ‘any’ to denote any IP
address:
any
This entry matches every IP address, no use in adding more entries to this
list.
Would you like to configure another list? [no]:
Enter IP access-class [0]:
1
Enter Telnet access-class [0]:
2
EXAMPLE 2:
This example skips the first section of the dialog (creating/modifying), and proceeds directly to assign
existing ACLs.
Would you like to enter the Access lists configuration menu? [no]:
y
Would you like to
create new Access lists or modify existing lists? [no]:
Enter IP access-class [0]:
10
Enter Telnet access-class [0]:
22