<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Restrict management access to VOSS switches using a firewall in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121050#M3156</link>
    <description>&lt;P&gt;I'd like to restrict access for management to VOSS switches using a firewall. The firewall rules will not be an issue. I'm running VOSS 8.10.x on all VOSS switches. So they have management CLIP addresses, which are separate from Source IP, and loopback addresses. I'm moving away from ACL's and access-lists, which are on the switches now.&lt;/P&gt;&lt;P&gt;The current code is:&lt;/P&gt;&lt;P&gt;mgmt clip vrf GlobalRouter&lt;BR /&gt;ip address 10.10.10.41/32&lt;BR /&gt;enable&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;I noticed there is a reserved vlan (4090) with the management CLIP address on it. Can I use that as part of the solution?&lt;/P&gt;&lt;P&gt;I've tried to find some information on this, but I guess my Google-fu is lacking.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jan 2026 16:59:46 GMT</pubDate>
    <dc:creator>XTRMUser</dc:creator>
    <dc:date>2026-01-06T16:59:46Z</dc:date>
    <item>
      <title>Restrict management access to VOSS switches using a firewall</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121050#M3156</link>
      <description>&lt;P&gt;I'd like to restrict access for management to VOSS switches using a firewall. The firewall rules will not be an issue. I'm running VOSS 8.10.x on all VOSS switches. So they have management CLIP addresses, which are separate from Source IP, and loopback addresses. I'm moving away from ACL's and access-lists, which are on the switches now.&lt;/P&gt;&lt;P&gt;The current code is:&lt;/P&gt;&lt;P&gt;mgmt clip vrf GlobalRouter&lt;BR /&gt;ip address 10.10.10.41/32&lt;BR /&gt;enable&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;I noticed there is a reserved vlan (4090) with the management CLIP address on it. Can I use that as part of the solution?&lt;/P&gt;&lt;P&gt;I've tried to find some information on this, but I guess my Google-fu is lacking.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 16:59:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121050#M3156</guid>
      <dc:creator>XTRMUser</dc:creator>
      <dc:date>2026-01-06T16:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict management access to VOSS switches using a firewall</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121055#M3158</link>
      <description>&lt;P&gt;Try access policy, example:&lt;/P&gt;&lt;P&gt;access-policy 2&lt;BR /&gt;access-policy 2 network 10.100.51.0 24&lt;BR /&gt;access-policy 2 access-strict&lt;BR /&gt;access-policy 2 accesslevel rwa&lt;BR /&gt;access-policy 2 ssh&lt;BR /&gt;access-policy 2 telnet&lt;BR /&gt;access-policy 2 snmpv3&lt;BR /&gt;access-policy 2 ftp&lt;BR /&gt;access-policy 2 http&lt;BR /&gt;access-policy 2 snmp-group readgrp snmpv2c&lt;BR /&gt;access-policy 2 snmp-group v1v2grp snmpv2c&lt;BR /&gt;access-policy 2 enable&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 13:39:20 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121055#M3158</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2026-01-07T13:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict management access to VOSS switches using a firewall</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121062#M3161</link>
      <description>&lt;P&gt;I have access-policies in place, as well as filters. But to make it easier on my coworkers, who don't understand access policies and filters, but do understand firewall rules, I'm switching.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 21:15:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/restrict-management-access-to-voss-switches-using-a-firewall/m-p/121062#M3161</guid>
      <dc:creator>XTRMUser</dc:creator>
      <dc:date>2026-01-07T21:15:23Z</dc:date>
    </item>
  </channel>
</rss>

