<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Policys .pol for Telnet/SSH/WEB access in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23142#M2176</link>
    <description>Create Date: Apr 19 2012  2:59PM&lt;BR /&gt;
&lt;BR /&gt;
 Since the telnet access rule can only recognize source-address modifier. Can you modify your policy to include the following in the Mgmt_deny and let me know if that works for you.&lt;BR /&gt;
&lt;BR /&gt;
 source-address 0.0.0.0/0;&lt;BR /&gt;
&lt;BR /&gt;
  (from Arpit_Bhatt)</description>
    <pubDate>Wed, 08 Jan 2014 05:52:00 GMT</pubDate>
    <dc:creator>EtherNation_Use</dc:creator>
    <dc:date>2014-01-08T05:52:00Z</dc:date>
    <item>
      <title>Policys .pol for Telnet/SSH/WEB access</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23141#M2175</link>
      <description>Create Date: Apr 19 2012  7:41AM&lt;BR /&gt;
&lt;BR /&gt;
I cannot seem to lock down my Extreme 450e stack.&lt;BR /&gt;
&lt;BR /&gt;
 I have created Mgmt.pol as per the below&lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
 entry Mgmt_allow {&lt;BR /&gt;
 &lt;BR /&gt;
 if {&lt;BR /&gt;
 &lt;BR /&gt;
 source-address 192.168.1.249/32;&lt;BR /&gt;
 &lt;BR /&gt;
 source-address x.x.x.x/28;&lt;BR /&gt;
 &lt;BR /&gt;
 source-address y.y.y.y/32;&lt;BR /&gt;
 &lt;BR /&gt;
 } then {&lt;BR /&gt;
 &lt;BR /&gt;
 permit;&lt;BR /&gt;
 &lt;BR /&gt;
 }&lt;BR /&gt;
 &lt;BR /&gt;
 }&lt;BR /&gt;
 &lt;BR /&gt;
 entry Mgmt_deny {&lt;BR /&gt;
     if {&lt;BR /&gt;
     } then {&lt;BR /&gt;
         deny;&lt;BR /&gt;
     }&lt;BR /&gt;
 }&lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
 I have then &lt;BR /&gt;
&lt;BR /&gt;
 Slot-1 xxxx # check policy Mgmt&lt;BR /&gt;
 Policy file check successful.&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
 then&lt;BR /&gt;
&lt;BR /&gt;
  configure telnet access-profile Mgmt&lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
 however I can still telnet to the device. Could I ask what I am doing wrong.&lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
  (from lee_byatt)</description>
      <pubDate>Wed, 08 Jan 2014 05:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23141#M2175</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: Policys .pol for Telnet/SSH/WEB access</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23142#M2176</link>
      <description>Create Date: Apr 19 2012  2:59PM&lt;BR /&gt;
&lt;BR /&gt;
 Since the telnet access rule can only recognize source-address modifier. Can you modify your policy to include the following in the Mgmt_deny and let me know if that works for you.&lt;BR /&gt;
&lt;BR /&gt;
 source-address 0.0.0.0/0;&lt;BR /&gt;
&lt;BR /&gt;
  (from Arpit_Bhatt)</description>
      <pubDate>Wed, 08 Jan 2014 05:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23142#M2176</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: Policys .pol for Telnet/SSH/WEB access</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23143#M2177</link>
      <description>Create Date: Apr 19 2012  3:01PM&lt;BR /&gt;
&lt;BR /&gt;
 Also try using counters and see if the policy is being hit.&lt;BR /&gt;
&lt;BR /&gt;
  (from Arpit_Bhatt)</description>
      <pubDate>Wed, 08 Jan 2014 05:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23143#M2177</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: Policys .pol for Telnet/SSH/WEB access</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23144#M2178</link>
      <description>Create Date: Apr 20 2012  1:27AM&lt;BR /&gt;
&lt;BR /&gt;
Looks a bit complicated to me, try the form:&lt;BR /&gt;
&lt;BR /&gt;
entry Mgmt_allow {&lt;BR /&gt;
    if match any {&lt;BR /&gt;
        source-address x.x.x.x/x;&lt;BR /&gt;
        source-address y.y.y.y/y;&lt;BR /&gt;
    } then {&lt;BR /&gt;
        permit;&lt;BR /&gt;
    }&lt;BR /&gt;
}&lt;BR /&gt;
&lt;BR /&gt;
By the way, this is fine for SSH/telnet but doesn't work for web access control - you can't use a policy file for that you have to enter it on the CLI as an access list.  I have moaned about this many times but they haven't fixed it yet.  (from David_Rickard)</description>
      <pubDate>Wed, 08 Jan 2014 05:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/policys-pol-for-telnet-ssh-web-access/m-p/23144#M2178</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:52:00Z</dc:date>
    </item>
  </channel>
</rss>

