cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
758
Views
0
Helpful
5
Replies

NX7K Mgmt Interface Security

zekebashi
Level 4
Level 4


Hello,

We ran a vulnerability test against the mgmt interface on the NX7K and the results came back showing that a number of services, such as SSH, DHCPs, NTP, BGP, and SNMP that are open. Are these services/ports listening to these services by default?

Thanks in advance.

Best, ~zK

5 Replies 5

Collin Clark
VIP Alumni
VIP Alumni

Typically no, but it also depends on what Supervisor you are running. Some include a CoPP policy and some have a CMP. I assume your testing against the admin VDC?

We have dual N7K-SUP2. We don't have CoPP enabled/configured. I am planning on implementing iACLs on the ingress interfaces that connect the VDC to our ISP. Are there any other suggestions to disable/deny ssh and other services to access the mgmt interface?

Thanks, ~zK  

The easiest way is to disable the service(s).

no feature [ssh,telnet,etc]

How would one ssh into the vdc/switch if the ssh feature is disabled? 

The way I set them up is to only enable services on the Admin VDC and from there I can jump to the other VDC's.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card