Qtech QSW-2910-09T-POE-AC/DC [160/212] Administration ip address restriction

Qtech QSW-2910-09T-POE-AC/DC [160/212] Administration ip address restriction
+7(495) 797-3311 www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
160
System supports VCT auto-test. When vct auto-test enables, once detecting link down, vct
auto-runs, and the test result will keep down to syslog.
VCT test command in global/ interface configuration command:
vct run
For example:
!Vct run forinterface Ethernet 0/1
QTECH(config-if-ethernet-0/0/1)#vct run
13.4.6 Administration IP address restriction
Managed ip address restriction can restrict host IP address or some network interface of
switch by restricting web, telnet and snmp agent, but other IP address without configuration
cannot manage switch. By default, three server possess an address interface of 0.0.0.0, so
users of any IP address can manage switch. Different IP address and mask mean different
information. The mask in reverse which is 0.0.0.0 means host address, or it means network
interface. 255.255.255.255 means all hosts. When enabling a configuration, an item of 0.0.0.0
must be deleted. When receiving a packet, judge the IP address whether it is in the range of
managed IP address. If it does not belong to it, drop the packet and shutdown telnet
connection.
login-access-list { web | snmp | telnet } ip-address wildcard
Web means accessing IP address restriction of web server; snmp means accessing IP
address restriction of snmp agent; telnet means accessing IP address restriction of telnet;
ipaddress means IP address; wildcard means mask wildcard which is in the form of mask in
reverse. 0 means mask this bit, and 1 meams does not mask this bit. When mask in reserve is
0.0.0.0, it means host address, and 255.255.255.255 means all hosts. Use the no command to
delete corresponding item.
For example:
!Configure ip address allowed by telnet management system to be
192.168.0.0/255.255.0.0
QTECH(config)#login-access-list telnet 192.168.0.0 0.0.255.255
QTECH(config)#no login-access-list telnet 0.0.0.0 255.255.255.255
Use show login-access-list command to display all ip address allowed by web, snmp, telnet
management system.
show login-access-list
13.4.7 The number of Telnet user restriction
Configure the max number of Telnet users. This function can restrict the number of Telnet user
(0-5) to enter privileged mode at the same time. The user logged in without entering privileged

Содержание

Скачать