Configuring Access Profiles
Use the Access Profiles page to create an access profile and to add its first rule. If the access profile only contains a single rule, you are finished. To add additional rules to the profile, use the Profile Rules page.
To add an access profile or select a different active access profile:
- Click Security > Management Access Method > Access Profiles.
The Access Profiles Table displays all of the access profiles, active and inactive.
- To change the active access profile, select a profile from the Active Access Profile drop-down menu and click Apply. This makes the selected profile as the active access profile.
NOTE A caution message appears if you selected Console Only. If you continue, you are immediately disconnected from the web-based interface and can only access the switch through the console port.
NOTE If you selected any other access profile, a caution message appears warning you that, depending on the selected access profile, you might be disconnected from the web-based interface.
- To add a new access profile and one rule, click Add.
- Enter the following information:
- Access Profile Name—Enter the access profile name.
- Rule Priority—Enter the rule priority. When the packet is matched to a rule, user groups are either granted or denied access to the switch. The rule priority is essential to matching packets to rules, as packets are matched on a first-match basis. One is the highest priority.
- Management Method—Select the management method for which the rule is defined. Users with this access profile can only access the switch by using the management method selected. The options are:
- All—Assigns all management methods to the rule.
- Telnet—Users requesting access to the switch, who meet the Telnet access profile criteria, are permitted or denied access.
- Secure Telnet (SSH)—Users requesting access to the switch, who meet the SSH access profile criteria, are permitted or denied access.
- HTTP—Assigns HTTP access to the rule. Users requesting access to the switch, who meet the HTTP access profile criteria, are permitted or denied.
- Secure HTTP (HTTPS)—Users requesting access to the switch, who meet the HTTPS access profile criteria, are permitted or denied.
- SNMP—Users requesting access to the switch, who meet the SNMP access profile criteria are permitted or denied.
- Action—Select the action attached to the rule. The options are:
- Applies to Interface—Select the interface attached to the rule. The options are:
- Applies to Source IP Address—Select the type of source IP address to which the access profile applies. The options are:
- IP Version—Select either Version 4 or Version 6 to define the source IP address.
- IP Address—Enter the source IP address.
- Mask—Select the format for the subnet mask for the source IP address, and enter a value in one of the fields:
- Click Apply. The access profile is created, and the Running Configuration is updated.