Restricting telnet access to a specific vlan, Restricting snmp access to a specific vlan – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 28

Advertising
background image

NOTE
You need to configure telnet with the enable telnet authentication local command to enable only a
certain number of telnet login attempts.

Changing the login timeout period for Telnet sessions

By default, the login timeout period for a Telnet session is 2 minutes. To change the login timeout
period, use the following command.

device(config)#telnet login-timeout 5

Syntax: [no] telnet login-timeout minutes

For minutes , enter a value from 1 to 10. The default timeout period is 2 minutes.

Restricting remote access to the device tospecific VLAN IDs

You can restrict management access to a Brocade device to ports within a specific port-based VLAN.
VLAN-based access control applies to the following access methods:

• Telnet access
• SNMP access
• TFTP access

By default, access is allowed for all the methods listed above on all ports. Once you configure security
for a given access method based on VLAN ID, access to the device using that method is restricted to
only the ports within the specified VLAN.

VLAN-based access control works in conjunction with other access control methods. For example,
suppose you configure an ACL to permit Telnet access only to specific client IP addresses, and you
also configure VLAN-based access control for Telnet access. In this case, the only Telnet clients that
can access the device are clients that have one of the IP addresses permitted by the ACL and are
connected to a port that is in a permitted VLAN. Clients who have a permitted IP address but are
connected to a port in a VLAN that is not permitted still cannot access the device through Telnet.

Restricting Telnet access to a specific VLAN

To allow Telnet access only to clients in a specific VLAN, enter a command such as the following.

device(config)#telnet server enable vlan 10

The command in this example configures the device to allow Telnet management access only to
clients connected to ports within port-based VLAN 10. Clients connected to ports that are not in VLAN
10 are denied management access.

Syntax: [no] telnet server enable vlan vlan-id

Restricting SNMP access to a specific VLAN

To allow SNMP access only to clients in a specific VLAN, enter a command such as the following.

device(config)#snmp-server enable vlan 40

Changing the login timeout period for Telnet sessions

28

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03

Advertising