This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
networking:switch:zyxel_gs1910 [2014/09/20 14:16] gcooper |
networking:switch:zyxel_gs1910 [2015/08/12 09:20] (current) gcooper |
||
---|---|---|---|
Line 7: | Line 7: | ||
http:// | http:// | ||
- | Support Notes: ftp:// | + | **Support Notes**: ftp:// |
+ | |||
+ | **CLI Reference**: | ||
===== Firmware Updates ===== | ===== Firmware Updates ===== | ||
Line 17: | Line 19: | ||
==== Default Login Details ==== | ==== Default Login Details ==== | ||
- | |IP Address | + | |IP Address |
- | |User Name |admin | + | |User Name |admin |
- | |Password | + | |Password |
- | |Serial Console |115200, | + | |Serial Console |115200, |
+ | |Serial Cable | ||
==== CLI Basics ==== | ==== CLI Basics ==== | ||
- | < | + | Reset to factory defaults, at boot up: |
+ | < | ||
+ | ctrl-c | ||
+ | default | ||
+ | reset | ||
</ | </ | ||
Line 115: | Line 122: | ||
==== Example Application ==== | ==== Example Application ==== | ||
- | We have created a port-based VLAN on switch ports 1-6 to use a section of the switch as a DMZ. | + | - We have created a port-based VLAN on switch ports 1-6 to use a section of the switch as a DMZ. |
+ | - We have a primary Internet connection via cable modem connected to port 1. | ||
+ | - We have a server' | ||
+ | - We have a router' | ||
+ | - For security reasons, we need to limit access to the server' | ||
- | We have a primary Internet connection via cable modem connected to port 1. | + | ==== Create an ACL Policy ==== |
- | We have a server' | + | :!: Here we create |
- | We have a router' | + | :!: The order of the ACEs is important. |
- | For security reasons, we need to limit access | + | - The first ACE permits traffic from the IPMI device |
- | + | - Set the 'Policy Filter' | |
- | ==== Create an ACE ==== | + | - Use a ' |
+ | - Set the 'Frame Type' | ||
+ | - Set the destination IP address or subnet as the IPMI support provider' | ||
+ | - Set the ' | ||
+ | - The second | ||
+ | - Set the ' | ||
+ | - Use the same ' | ||
+ | - Set the 'Frame Type' to ' | ||
+ | - Change the ' | ||
**Configuration -> Security -> Network -> ACL -> Access Control List -> Add** | **Configuration -> Security -> Network -> ACL -> Access Control List -> Add** | ||
- | We create | + | {{ : |
+ | |||
+ | {{ : | ||
+ | |||
+ | ==== Apply the ACE ==== | ||
+ | |||
+ | :!: We apply the ACL policy to the port with the IPMI device. | ||
+ | |||
+ | :!: We deny all other traffic on that port using an ACE (above), not by changing | ||
+ | |||
+ | **Configuration -> Security -> Network -> ACL -> Ports** | ||
- | {{ : | + | - Enter the ID of the ACL policy you just created in the Policy ID field of the port with the IPMI device. |
+ | - Leave the ' | ||
+ | {{ : |