Management interface

Information

The built-in management interface is intended to provide a means to access and manage the switch from anetwork segregated from production traffic. Only stations on the segregated management network can gain management access to the switch. This sharply limits the universe of devices that can attempt unauthorized access.

In the switch software, the management interface is logically separated from the rest of the switch by means of virtual routing and forwarding (VRF); features that are intended to be used on the management interface are assigned to the dedicated mgmt VRF instance. Several management services can be configured to use the mgmt VRF rather than normal switch ports, as illustrated in several examples above.

Traffic cannot be routed between the management interface and normal switch ports, and the management interface can be assigned a dedicated gateway address. The management interface is enabled by default.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To configure the management interface with a static IP address, gateway, and DNS:

switch(config)# interface mgmt
switch(config-if-mgmt)# ip static 10.1.1.5/24
switch(config-if-mgmt)# default-gateway 10.1.1.1
switch(config-if-mgmt)# nameserver 10.0.1.10 10.0.1.11

To use DHCP instead:

switch(config)# interface mgmt
switch(config-if-mgmt)# ip dhcp

To show the status of the management interface:

switch# show interface mgmt
Address Mode : static
Admin State : up
Mac Address : d0:67:26:11:11:11
IPv4 address/subnet-mask : 10.1.1.5/24
Default gateway IPv4 : 10.1.1.1
IPv6 address/prefix :
IPv6 link local address/prefix : fe80::d267:2611:1111:1111/64
Default gateway IPv6 :
Primary Nameserver : 10.0.1.10
Secondary Nameserver : 10.0.1.11

See Also

https://support.hpe.com/hpesc/public/docDisplay?docId=a00053695en_us

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(13)

Plugin: ArubaOS

Control ID: 36f864053ac64d9e1d446cbfa426d75c27bbc3d90ab85589225773928d6754e4