<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limiting Management Access to AP in Aerohive Migrated Content</title>
    <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89915#M12492</link>
    <description>&lt;P&gt;Yes, you can turn off the Web access by going into the policy &amp;gt; additional settings &amp;gt; management options &amp;gt; tick “Disable WebUI without disabling CWP”&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2020 19:22:03 GMT</pubDate>
    <dc:creator>Ash_Finch</dc:creator>
    <dc:date>2020-06-26T19:22:03Z</dc:date>
    <item>
      <title>Limiting Management Access to AP</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89910#M12487</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using 12.8.2.2-NGVASEP18.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to learn about management access to my AP and how to limit it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://thehivecommunity.aerohive.com/s/article/How-to-Connect-to-an-AP-using-SSH describes how to connect to an AP via SSH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But there's also an HTTP/HTTPS web user interface.&lt;/P&gt;&lt;P&gt;I don't want to expose those to anyone but the management systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;B&gt;Device SSH Availability"&lt;/B&gt; in the docs &lt;B&gt;(&lt;/B&gt;http://docs.aerohive.com/330000/docs/help/english/ng/Content/gui/configuration/configuring-device-ssh-availability.htm)  tells me that I have to eneable SSH before I can use it... well, on my device it is not enabled, nor did I enable the WUI. Still I can log in via both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What is the idea behind the "Device SSH Availability" setting?&lt;/LI&gt;&lt;LI&gt;How can I limit management (SSH / WUI / whatever there might be) by an ACL?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably I can create a firewall policy, but I believe that management access should be handeled by an ACL at first.... how can this be done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Armin&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 23:07:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89910#M12487</guid>
      <dc:creator>wies_hays</dc:creator>
      <dc:date>2019-01-28T23:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Management Access to AP</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89911#M12488</link>
      <description>&lt;P&gt;The setting for SSH availability in the Global Settings of the HiveManager is intended to enable to Proxy SSH connections through HiveManager to a target AP. Once this option is enabled in the HiveManager, Going into the device configuration of any Aerohive device will show "SSH" under "Additional Device Settings".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The physical Aerohive devices have SSH enabled by default. Regarding restricting SSH access, ideally, Aerohive devices would be placed in their our management VLAN. Client traffic would be segmented off in their own VLAN, with firewall rules preventing clients from access devices in the Aerohive management&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 00:00:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89911#M12488</guid>
      <dc:creator>michael_bernard</dc:creator>
      <dc:date>2019-01-29T00:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Management Access to AP</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89912#M12489</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for clarifying this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately we don't have a Management VLAN on which a gateway could filter out unwanted management access.&lt;/P&gt;&lt;P&gt;On all of our other devices we set up ACLs which limit management connection attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, on HiveOS devices this cannot be done?&lt;/P&gt;&lt;P&gt;Can you please confirm that the only way to limit management access is through the firewall on that HiveOS device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Armin&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 18:19:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89912#M12489</guid>
      <dc:creator>wies_hays</dc:creator>
      <dc:date>2019-01-29T18:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Management Access to AP</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89913#M12490</link>
      <description>&lt;P&gt;We have the same challenge: It's not possible to disable SSH-access to the APs. Our env is: Hivemanager 19.5.1.7-NGVA, AP550 with HiveOS 10.0r8. We unchecked "Enable SSH" in the corresponding Traffic Filter, we unchecked "Enable SSH" in the Optional Settings of the AP and we unchecked "Enable SSH" under SSH Availability in the Global Settings. The AP still accepts SSH-connections. What else has to be done?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 21:12:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89913#M12490</guid>
      <dc:creator>reinhardg</dc:creator>
      <dc:date>2020-02-24T21:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Management Access to AP</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89914#M12491</link>
      <description>&lt;P&gt;We’re looking to do something similar at the moment.&lt;BR /&gt; Our APs are accessible internally via HTTP/HTTPS, and want to turn that off, so they’re only accessible via SSH or through Aerohive.&lt;BR /&gt; Is this even possible?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 21:21:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89914#M12491</guid>
      <dc:creator>mlee</dc:creator>
      <dc:date>2020-06-22T21:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Management Access to AP</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89915#M12492</link>
      <description>&lt;P&gt;Yes, you can turn off the Web access by going into the policy &amp;gt; additional settings &amp;gt; management options &amp;gt; tick “Disable WebUI without disabling CWP”&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 19:22:03 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/limiting-management-access-to-ap/m-p/89915#M12492</guid>
      <dc:creator>Ash_Finch</dc:creator>
      <dc:date>2020-06-26T19:22:03Z</dc:date>
    </item>
  </channel>
</rss>

