System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Management plane protection features

Want to summarize with AI?

Log in

Introduces management plane protection features, covering task permission requirements, behavior restrictions, inband and out-of-band interfaces, peer filtering, protection mechanisms, management planes, key benefits, configuration processes, interface setup tasks, example configurations, and supplemental references.


A Management Plane Protection (MPP) feature is a security feature that

  • restricts the interfaces on which network management packets can enter a device

  • lets an operator designate one or more router interfaces as management interfaces, and

  • causes only designated management interfaces to accept management traffic destined for the device.


Requirement: Verify management-plane task permissions

Verify that your user group is associated with a task group that includes the required task IDs before you configure management plane protection. This ensures that you have the necessary permissions to use all management plane protection commands.


Restriction: Account for management plane protection restrictions

Account for the following Management Plane Protection (MPP) restrictions whenever you design, enable, modify, or troubleshoot the management-plane configuration:

  • MPP does not track denied or dropped protocol requests.

  • MPP configuration does not enable protocol services; it only makes enabled services available on different interfaces. Protocols must be explicitly enabled.

  • Management requests received on inband interfaces are not necessarily acknowledged on the same interface.

  • Route Processor (RP) interfaces are designated as out-of-band interfaces by default and can be configured under MPP.

  • MPP configuration changes do not affect active sessions established before the changes.

  • MPP controls only incoming management requests for specific protocols (such as TFTP, Telnet, SNMP, SSH, and HTTP).

  • MPP does not support MIB.

  • In an MPLS L3VPN, if a VRF interface is attached under MPP, it applies the VRF filter on incoming interfaces through LPTS. Incoming packets from a core interface with a different VRF are not allowed by MPP.


Management plane protection

A management plane protection feature is a security mechanism that

  • distinguishes inband interfaces from out-of-band interfaces

  • enables peer filtering by clarifying the relationship between the control and management planes, and

  • supports, enables, and filters management protocols for improved network defense.

Additional reference information

Before you enable the MPP feature, review the concepts in the related child topics to fully understand configuration options, interface types, and protocol support.


Inband management interfaces

An inband management interface is a Cisco IOS XR physical or logical interface that

  • processes management packets

  • processes data-forwarding packets, and

  • processes packets as a shared management interface.


Out-of-band management interfaces

An out-of-band management interface is an interface that

  • allows only management protocol traffic to be forwarded or processed

  • prevents forwarding or customer traffic from interfering with router management and significantly reduces the possibility of denial-of-service attacks, and

  • forwards traffic between out-of-band interfaces, terminates management packets destined for the router, and participates in dynamic routing protocols.

Additional reference information

The service provider connects to the router's out-of-band interfaces and builds an independent overlay management network with all the routing and policy tools that the router can provide.


Peer filters on interfaces

A peer filter is an interface option that

  • allows management traffic from a specific peer

  • allows management traffic from a range of peers, and

  • provides a more specific source restriction than allowing all peers.


Control plane protection

A control plane is a collection of route-processor processes that

  • runs at the process level

  • provides high-level control for most Cisco IOS XR software functions, and

  • handles traffic directly or indirectly destined for the router while providing the Control Plane Infrastructure in which MPP operates.


Management planes

A management plane is a layer of a communication architecture that

  • serves as one of three planes responsible for managing network devices

  • coordinates functions among the management, control, and data planes, and

  • supports device monitoring and command-line interface (CLI) access through management protocols.

Additional reference information

Examples of protocols processed in the management plane include Simple Network Management Protocol (SNMP), Telnet, HTTP, Secure HTTP (HTTPS), and Secure Shell (SSH). These management protocols are used for device monitoring and CLI access. Restricting access to devices to internal sources (trusted networks) is critical.


Management plane rotection feature

The MPP features are management-traffic protection features that

  • are disabled by default, along with their management protocols, and are enabled when an interface is configured as inband or out-of-band

  • allow management traffic by default only on RP and standby RP Ethernet interfaces and on interfaces manually configured for MPP, while all other interfaces drop management packets destined for the device, and

  • support SSHv2, all SNMP versions, Telnet, TFTP, HTTP, and HTTPS, and permit modification or deletion of management interfaces after configuration.

Additional reference information

  • If MPP is disabled and a protocol is activated, all interfaces can pass management traffic.

  • Logical interfaces, and other interfaces that are not present on the data plane, filter packets based on the ingress physical interface.

  • MPP supports the following management protocols:

    • SSHv2

    • SNMP, all versions

    • Telnet

    • TFTP

    • HTTP

    • HTTPS


Key benefits of management plane protection

MPP provides these benefits:

  • Provides greater access control for managing a device than allowing management protocols on all interfaces.

  • Improves performance for data packets on non-management interfaces.

  • Supports network scalability.

  • Simplifies the task of using per-interface access control lists (ACLs) to restrict management access to the device.

  • Reduces the number of ACLs needed to restrict access to the device.

  • Prevents packet floods on switching and routing interfaces from reaching the CPU.


How management plane protection works

Configuring MPP helps prevent unauthorized access to the router's management functions by restricting which interfaces and peers can send management traffic. Inband refers to management traffic carried along with regular data, while out-of-band uses dedicated management-only interfaces and VRFs.

Summary

The key components involved in the process are:

  • Operator: Designates and configures inband or out-of-band management interfaces.

  • MPP: Controls incoming management requests for protocols such as SSHv2, SNMP, Telnet, TFTP, HTTP, and HTTPS.

  • Peer filtering mechanism: Limits management traffic to specific peers or peer ranges for enhanced security.

MPP ensures secure access to management functions on a Cisco 8000 Series Router by separating inband and out-of-band management interfaces and limiting which interfaces accept management traffic.

Workflow

These stages describe how management plane protection works.

  1. Configure the inband management interface, enable the required protocol, optionally restrict the protocol to a peer or peer range, and commit the configuration.

  2. Configure the out-of-band VRF and management interface, enable the required protocol, optionally restrict the protocol to a peer or peer range, and commit the configuration.

  3. Verify the resulting MPP interface or VRF state with the appropriate show mgmt-plane command.

Result

MPP accepts management packets only on the default or explicitly configured management interfaces. All other interfaces drop management packets destined for the device, enhancing the router’s security.


Configure an inband management plane protection interface

Enable Telnet management access for a specific IPv4 range on an inband interface.

Use this task on a newly added or already operating device. An inband management interface processes both management and data-forwarding packets. In this example, fourHundredGigE 0/0/0/0 is configured as an inband interface to allow Telnet from the specified peer range.

Before you begin

Ensure that your user group includes the task IDs required for the configuration commands.

If configuring an inband MPP interface in a non-default VRF, perform these additional steps:

  • Configure the interface under the non-default inband VRF.

  • Configure the global inband VRF.

  • For Telnet, configure the Telnet VRF server for the inband VRF.

Procedure

  1. Specify the interface to configure as an inband interface and allow Telnet protocol on the inband interface.

    Example:

    Router#configure terminal
    Router(config)#control-plane
    Router(config-ctrl)#management-plane
    Router(config-mpp)#inband
    Router(config-mpp-inband)#interface fourHundredGigE 0/0/0/0
    Router(config-mpp-inband-if)#allow telnet peer
    Router(config-telnet-peer)#address ipv4 10.1.0.0/16
    Router(config-telnet-peer)#commit

    FourHundredGigE 0/0/0/0 is configured as an inband interface. Use the interface all command form to configure all interfaces as inband interfaces.

    Telnet is configured on the inband interface. Use the allow all command form to enable all protocols.

  2. Verify the inband interface configuration.

    Running Configuration

    The following is a sample output of the show mgmt-plane command for the inband interface fourHundredGigE 0/0/0/0.

    Example:

    Router# show mgmt-plane inband interface fourHundredGigE 0/0/0/0
    
    interface - fourHundredGigE 0/0/0/0
            telnet configured -
                    peer v4 allowed - 10.1.0.0/16

The specified inband interface accepts Telnet management traffic from the configured IPv4 peer range (10.1.0.0/16).


Configure an out-of-band management plane protection interface

Configure an out-of-band interface in VRF target to accept TFTP management traffic from the IPv6 peer address 33::33.

Use this task for devices that have just been added to the network or are already operational. An out-of-band interface only forwards or processes management protocol traffic, providing isolation from production traffic. In this example, fourHundredGigE 0/0/0/3 is set up for VRF target and permits TFTP traffic from a specific IPv6 peer.

Before you begin

Ensure that your user group includes the task IDs required for the configuration commands.

The following preliminary tasks may be needed:

  • Configure the interface under the out-of-band VRF.

  • Configure the global out-of-band VRF.

  • For a specific protocol, configure the protocol VRF server for the out-of-band VRF.

Procedure

  1. Configure out-of-band management plane protection on an interface.

    Example:

    Router#configure terminal
    Router(config)#control-plane
    Router(config-ctrl)#management-plane
    Router(config-mpp)#out-of-band
    Router(config-mpp-outband)#vrf target
    Router(config-mpp-outband)#interface fourHundredGigE 0/0/0/3
    Router(config-mpp-outband-if)#allow tftp peer
    Router(config-tftp-peer)#address ipv6 33::33
    Router(config-tftp-peer)#commit

    FourHundredGigE 0/0/0/3 is configured as an out-of-band interface for VRF target. Use the interface all command form to configure all interfaces as out-of-band interfaces.

    TFTP is configured on the out-of-band interface. Use the allow all command form to enable all protocols.

  2. Verify the out-of-band VRF configuration.

    Running Configuration

    The following is a sample output of the show mgmt-plane out-of-band vrf command.

    Example:

    Router# show mgmt-plane out-of-band vrf
    Management Plane Protection -
            out-of-band VRF - target

The specified out-of-band interface accepts TFTP management traffic exclusively from the configured IPv6 peer (33::33), enhancing the control and security of network management functions.


Examples of management plane protection configurations

MPP allows administrators to restrict access to the device’s management plane, enhancing security by controlling which interfaces can accept management traffic. The following examples illustrate both inband and out-of-band configuration scenarios for MPP.


Management plane protection configuration and verification example

Use this example as a reference when configuring inband and out-of-band interfaces under Management Plane Protection.

Configuration

The example configures inband and out-of-band interfaces under MPP.

configure
 control-plane
  management-plane
   inband
    interface all
     allow SSH
     !
    interface fourHundredGigE 0/0/0/0
     allow all
     allow SSH
     allow Telnet peer
      address ipv4 10.1.0.0/16
     !
    !
    interface fourHundredGigE 0/0/0/0
     allow Telnet peer
      address ipv4 10.1.0.0/16
     !
    !
   !
   out-of-band
    vrf target
    interface fourHundredGigE 0/0/0/3
     allow TFTP peer
      address ipv6 33::33
     !
    !
   !
  !
 !
!

Verification output

The following output displays the configured management interfaces, allowed peers, and out-of-band VRF.

show mgmt-plane

Management Plane Protection

inband interfaces
----------------------

interface - fourHundredGigE 0/0/0/0
        ssh configured -
                All peers allowed
        telnet configured -
                peer v4 allowed - 10.1.0.0/16
        all configured -
                All peers allowed
interface - fourHundredGigE 0/0/0/0
        telnet configured -
                peer v4 allowed - 10.1.0.0/16

interface - all
        all configured -
                All peers allowed
outband interfaces
----------------------
interface - fourHundredGigE 0/0/0/3
        tftp configured -
                peer v6 allowed - 33::33

show mgmt-plane out-of-band vrf

Management Plane Protection -
        out-of-band VRF - target

Additional references

Use these references to find MPP commands, MIB information, standards and RFC status, and Cisco Technical Assistance.

The following sections provide references related to implementing Management Plane Protection.

Related Documents

Related topic

Document title

MPP commands: complete command syntax, command modes, command history, defaults, usage guidelines, and examples

Management Plane Protection Commands on System Security Command Reference for Cisco 8000 Series Routers.

Standards

Standards

Title

No new or modified standards are supported by this feature, and support for existing standards has not been modified by this feature.

—

MIBs

MIBs

MIBs link

—

To locate and download MIBs using Cisco IOS XR software, use the Cisco MIB Locator found at the following URL and choose a platform under the Cisco Access Products menu: http://cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml

RFCs

RFCs

Title

No new or modified RFCs are supported by this feature.

—

Technical Assistance

Description

Link

The Cisco Technical Support website contains thousands of pages of searchable technical content, including links to products, technologies, solutions, technical tips, and tools. Registered Cisco.com users can log in from this page to access even more content.

http://www.cisco.com/techsupport