User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Mesh Point CLI and Administrative Access
22
Password requirement for locally authenticating administrative
accounts are global and configurable (refer to Section 2.2.1).
If the you are changing the password for the account you are
currently logged on through, you will be returned to the
Login
prompt: re-enter the account username and enter the new
password to re-access the Mesh Point CLI.
2.2.5 Administrative IP Address Access Control List
NOTE: Pass-
through traffic is
unaffected by enabling
the administrative IP
address ACL.
If the administrative IP address ACL is enabled, it must include
the IP addresses of any device with which the Mesh Point will
exchange administrative-level traffic. If the relevant IP
addresses are not present on the administrative IP address
ACL when the list is enabled, Mesh Point functions that depend
on administrative access will not be able to perform the
necessary operation. Mesh Point functions that require
administrative IP address access include:
NOTE: To control
pass-through traf-
fic, the user can config-
ure packet filtering,
described in Section
4.6.3.
Mesh Point administration - remote log-on to the
management interface
IGMP - incoming multicast (Internet Group Management
Protocol) traffic
NTP - incoming Network Time Protocol server packets
DHCP - incoming Dynamic Host Configuration Protocol
unicast requests
DNS - incoming Domain Name System queries
CAUTION: If, while
remotely con-
nected, you enable
administrative IP-
address access control
without first adding
your IP address, your
session will be termi-
nated and the address
blocked until it is added
to the list of permitted
addresses or the func-
tion is disabled.
IPsec - incoming IKE (Internet Key Exchange) packets from
IPsec peers
L2TP - incoming Layer 2 Tunneling Protocol traffic
RADIUS - incoming traffic from locally authenticating
administrators, users, devices, and 802.1X supplicants
OCSP - incoming Online Certificate Status Protocol traffic
CRL - incoming Certificate Revocation List traffic
ICMP and ICMPv6 - incoming Internet Control Message
Protocol packets for IPv4 (ping and traceroute) and
IPv6 (neighbor discovery messages, etc.)
By default, administrative IP address access control is
disabled: administrators can log on remotely from any
network IP address, and administrative-level traffic is freely
permitted.
# show ipacl
IP Acl enabled: No
IP Address Description
------------------------- -----------------------------------------
192.168.1.47 admin
You can configure the Mesh Point to restrict administrative
access to a limited set of allowed IP addresses by adding one