cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
291
Views
0
Helpful
1
Replies

Catalyst 1000 / secureing management access

kralopafo
Level 1
Level 1

Hello,

I am still considering wheter to deploy Catalyst1000 or CBS350 switch at our small office(15-25 devices).
Switch have to be configured with multiple SVIs and DHCP server pools for each + few static routes.
I would like to secure MGMT access to the switch as much as I can, so my question is:

Is it possible to configure something like MGMT ACL on Catalyst1000 ?
- I mean to globally restrict access to Magamenet of the switch over ports 443/22 , only from certain IP/subnet.
Is there any possibility to configure Quiet-mode with some ACL that permits specific subnet to access MGMT during Quiet-period ?

I was reading dataheet and configuration guide for Catalyst1000, and they said supported are only "port-based" ACL.
Does it mean that the switch is somehow unable to benefit from advanced ACL features, that are necessary for functions like MGMT ACL or Quitem/period ACL ?

Thank you very much.

1 Reply 1

kralopafo
Level 1
Level 1

Actually, Im configurting my Catalyst 1000 and I'm surprised !
It is possible to configure ACL for: VTY line access, snmp-server community, quiet-mode.


Review Cisco Networking for a $25 gift card