Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
16-19
Cisco ASDM User Guide
OL-16647-01
Chapter 16 Configuring Management Access
Configuring Management Access Rules
Step 9 Click Apply.
The management station is configured and changes are saved to the running configuration.
Configuring SNMP Traps
To designate which traps the SNMP agent generates and how they are collected and sent to network
management stations, perform the following steps:
Step 1 From the Configuration > Device Management > Management Access > SNMP pane, click Configure
Traps.
The SNMP Trap Configuration dialog box appears.
Step 2 Click the SNMP events to notify through SNMP traps.
Step 3 Click OK.
The dialog box closes.
Step 4 Click Apply.
The SNMP traps are configured and the changes are saved to the running configuration.
Configuring Management Access Rules
Access Rules specifically permit or deny traffic to or from a particular peer (or peers) while Management
Access Rules provide access control for to-the-box traffic. For example, in addition to detecting IKE
Denial of Service attacks, you can block them using management access rules.
To add a Management Access Rule, perform the following steps:
Step 1 From the Configuration > Device Management > Management Access > Management Access Rules
pane, from the Add menu, click Add Management Access Rule.
The Add Management Access Rules dialog box appears.
Step 2 From the Interface drop-down list, choose an interface for applying the rule.
Step 3 In the Action field, click one of the following:
Permit (permits this traffic)
Deny (denies this traffic)
Step 4 In the Source field, choose Any, or click the ellipsis (...) to browse for an address.
Step 5 In the Service field, add a service name for the rule traffic, or click the ellipsis (...) to browse for a
service.
Step 6 (Optional) In the Description field, add a description for this management access rule.
Step 7 (Optional) If you want to receive log messages for this management access rule, check Enable Logging
and then from the Logging Level drop-down list, choose the level of logging to apply to this rule.