HP 6120XG HP ProCurve Series 6120 Blade Switches IPv6 Configuration Guide - Page 137

Configuring Authorized IP Managers for Switch Access

Page 137 highlights

Note IPv6 Management Security Features Authorized IP Managers for IPv6 Configuring Authorized IP Managers for Switch Access To configure one or more IPv6-based management stations to access the switch using the Authorized IP Managers feature, enter the ipv6 authorizedmanagers command Syntax: [no] ipv6 authorized-managers [ipv6-mask] [access ] access-method [all | ssh | telnet | web | snmp | tftp] Configures one or more authorized IPv6 addresses to access the switch, where: ipv6-mask specifies the mask that is applied to an IPv6 address to determine authorized stations. For more information, see "Using a Mask to Configure Authorized Management Stations" on page 6-5. Default: FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF. access specifies the level of access privilege granted to authorized stations. Applies only to access through telnet, SSH, and SNMP (version 1,2, and 3). Default: Manager. access-method [all | ssh | telnet | web | snmp | tftp] configures access levels by access method and IP address. Each management method can have its own set of authorized managers. Default: All Using a Mask to Configure Authorized Management Stations The ipv6-mask parameter controls how the switch uses an IPv6 address to determine the IPv6 addresses of authorized manager stations on your net­ work. For example, you can specify a mask that authorizes: ■ Single station access ■ Multiple station access Mask configuration is a method for determining the valid IPv6 addresses that are authorized for management access to the switch. In the Authorized IP Managers feature, the mask serves a different purpose than an IPv6 subnet mask and is applied in a different manner. Configuring Single Station Access To authorize only one IPv6-based station for access to the switch, enter the IPv6 address of the station and set the mask to FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF. 6-5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178

IPv6 Management Security Features
Authorized IP Managers for IPv6
Configuring Authorized IP Managers for Switch Access
To configure one or more IPv6-based management stations to access the
switch using the Authorized IP Managers feature, enter the
ipv6 authorized-
managers
command
Syntax:
[no] ipv6 authorized-managers
<ipv6-addr>
[
ipv6-mask
] [access <operator
| manager>] access-method [all | ssh | telnet | web | snmp | tftp]
Configures one or more authorized IPv6 addresses to access ±
the switch, where:±
ipv6-mask
specifies the mask that is applied to an IPv6 address ±
to determine authorized stations. For more information, see ±
“Using a Mask to Configure Authorized Management Stations” ±
on page 6-5. Default:
FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF
. ±
access <operator | manager>
specifies the level of access privilege ±
granted to authorized stations. Applies only to access through ±
telnet, SSH, and SNMP (version 1,2, and 3). Default:
Manager.±
access-method [all | ssh | telnet | web | snmp | tftp]
co
nfigures ±
access levels by access method and IP address. Each ±
management method can have its own set of authorized ±
managers. Default:
All±
Using a Mask to Configure Authorized Management
Stations
The
ipv6-mask
parameter controls how the switch uses an IPv6 address to
determine the IPv6 addresses of authorized manager stations on your net-
work. For example, you can specify a mask that authorizes:
Single station access
Multiple station access
Note
Mask configuration is a method for determining the valid IPv6 addresses that
are authorized for management access to the switch. In the Authorized IP
Managers feature, the mask serves a different purpose than an IPv6 subnet
mask and is applied in a different manner.
Configuring Single Station Access
To authorize only one IPv6-based station for access to the switch, enter the
IPv6 address of the station and set the mask to
FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF
.
6-5