Administrator Guide

Fabric OS Administrator’s Guide 227
53-1002920-02
Telnet protocol
7
Blocking Telnet
If you create a new policy using commands with just one rule, all the missing rules have an implicit
deny and you lose all IP access to the switch, including Telnet, SSH, and management ports.
Use the following procedure to block Telnet access.
1. Connect to the switch and log in using an account with admin permissions.
2. Clone the default policy by typing the ipFilter
--clone command.
switch:admin> ipfilter --clone BlockTelnet -from default_ipv4
3. Save the new policy by typing the ipFilter --save command.
switch:admin> ipfilter --save BlockTelnet
4. Verify the new policy exists by typing the ipFilter --show command.
switch:admin> ipfilter --show
5. Add a rule to the policy, by typing the ipFilter --addrule command.
switch:admin> ipfilter --addrule BlockTelnet -rule 1 -sip any -dp 23 -proto
tcp -act deny
ATTENTION
The rule number assigned must precede the default rule number for this protocol. For
example, in the defined policy, the Telnet rule number is 2. Therefore, to effectively block
Telnet, the rule number to assign must be 1.
If you choose not to use 1, you must delete the Telnet rule number 2 after adding this rule.
Refer to “Deleting a rule from an IP Filter policy” on page 259 for more information on deleting
IP filter rules.
6. Save the new IP filter policy by typing the ipfilter
--save command.
7. Verify the new policy is correct by typing the ipFilter
--show command.
8. Activate the new IP filter policy by typing the ipfilter
--activate command.
switch:admin> ipfilter --activate BlockTelnet
9. Verify the new policy is active (the default_ipv4 policy should be displayed as defined).
switch:admin> ipfilter --show
Name: default_ipv4, Type: ipv4, State: defined
Rule Source IP Protocol Dest Port Action
1 any tcp 22 permit
2 any tcp 23 permit
3 any tcp 80 permit
4 any tcp 443 permit
5 any udp 161 permit
6 any udp 123 permit
7 any tcp 600 - 1023 permit
8 any udp 600 - 1023 permit
Name: default_ipv6, Type: ipv6, State: defined
Rule Source IP Protocol Dest Port Action