Security Command Reference
88 7705 SAR OS System Management Guide
src-ip
Syntax src-ip ipv6-address/prefix-length
no src-ip
Context config>system>security>management-access-filter>ipv6-filter>entry
Description This command configures a source IPv6 address range to be used as an management access filter match
criterion.
To match on the source IP address, specify the address and prefix length; for example, 11::12/128.
The no form of the command removes the source IP address match criterion.
Default n/a
Parameters ipv6-address/prefix-length — the IPv6 address on the interface
Values ipv6-address x:x:x:x:x:x:x:x (eight 16-bit pieces)
x:x:x:x:x:x:d.d.d.d
x: [0 to FFFF]H
d: [0 to 255]D
prefix-length:1 to 128
src-port
Syntax src-port {port-id | cpm}
no src-port
Context config>system>security>management-access-filter>ip-filter>entry
config>system>security>management-access-filter>ipv6-filter>entry
Description This command restricts ingress management traffic to either the CSM Ethernet port or any other
logical port (port or channel) on the device.
When the source interface is configured, only management traffic arriving on those ports satisfy the
match criteria.
The no form of the command reverts to the default value.
Default any interface
Parameters port-id — the port ID
Values port-id: slot/mda/port[.channel]
bundle-id: bundle-type-slot/mda.bundle-num
bundle: keyword
type: ima | ppp
bundle-num: 1 to 32