


 



<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docwiki.cisco.com/w/skins/common/feed.css?270"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;feed=atom&amp;action=history</id>
		<title>Initial Remote Access to ACE Configuration Example - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;action=history"/>
		<updated>2013-05-22T09:08:33Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.16.0</generator>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;diff=24588&amp;oldid=prev</id>
		<title>Docwikibot: Bot: Adding {{Template:Required Metadata}}</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;diff=24588&amp;oldid=prev"/>
				<updated>2009-12-18T17:30:17Z</updated>
		
		<summary type="html">&lt;p&gt;Bot: Adding {{Template:Required Metadata}}&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 17:30, 18 December 2009&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;{{Template:Required Metadata}}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Purpose==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Purpose==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Configure remote access to allow telnet, ssh, and other mgmt protocols access to the ACE via the Admin context. &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Configure remote access to allow telnet, ssh, and other mgmt protocols access to the ACE via the Admin context. &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Docwikibot</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;diff=7870&amp;oldid=prev</id>
		<title>Pzimmerm: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;diff=7870&amp;oldid=prev"/>
				<updated>2008-12-04T18:37:23Z</updated>
		
		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 18:37, 4 December 2008&lt;/td&gt;
		&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Pzimmerm</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;diff=7869&amp;oldid=prev</id>
		<title>Pzimmerm: /* Related Information */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Initial_Remote_Access_to_ACE_Configuration_Example&amp;diff=7869&amp;oldid=prev"/>
				<updated>2008-12-02T18:19:59Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Related Information&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Purpose==&lt;br /&gt;
Configure remote access to allow telnet, ssh, and other mgmt protocols access to the ACE via the Admin context. &lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
In the typical scenario, the MSFC is used to route remote access connection from a client to the ACE.  It is recommended to have a dedicated VLAN for remote management when feasible; however, it is not required.  In fact, it is common to see a management service policy apply to client vlans when ACE is integrated into an existing network. &lt;br /&gt;
&lt;br /&gt;
[[Image:Inital Remote Access to ACE.jpg]]&lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
Remote access is denied by default on the ACE module.  To enable remote access you need to configure the following objects:&lt;br /&gt;
* class-map to classify the remote management traffic which can access the ACE control plane&lt;br /&gt;
* policy-map to allow the classified protocols&lt;br /&gt;
* interface vlan to receive the remote access connections&lt;br /&gt;
&lt;br /&gt;
To begin the configuration, use a console connection or session to the ACE from the Sup720 (session slot &amp;lt;#&amp;gt;proc 0).&lt;br /&gt;
It is common to allow all of the management protocols to the Admin context using the management policy-map with the default class.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;policy-map type management first-match unrestricted-remote-mgmt&lt;br /&gt;
  class class-default&lt;br /&gt;
    permit&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
However, if security is a concern ACE can be configured to only accept the require protocols from well defined hosts.  This follow example shows a common configuration where only ssh, snmp, and https management protocols are allowed.  &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;class-map type management match-any remote-access&lt;br /&gt;
  2 match protocol ssh any&lt;br /&gt;
  3 match protocol snmp any&lt;br /&gt;
  4 match protocol https any&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{note|To restrict access based on host, simply change the “any” to a well define host match. }}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;policy-map type management first-match remote-mgmt&lt;br /&gt;
  class remote-access&lt;br /&gt;
    permit&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{note|To further restrict access, policies can be used to deny remote access traffic.  Although policies to deny remote access traffic are not commonly used, they useful when one needs to allow a subnet remote access, and restrict a single host within that subnet.}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;interface vlan 10&lt;br /&gt;
  description &amp;quot;Client side connectivity&amp;quot;&lt;br /&gt;
  ip address 172.16.1.5 255.255.255.0&lt;br /&gt;
  service-policy input remote-mgmt&lt;br /&gt;
  no shutdown&lt;br /&gt;
&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 172.16.1.1&lt;br /&gt;
&lt;br /&gt;
Related 'show' commands &lt;br /&gt;
DC1-Cat6k1#show users&lt;br /&gt;
DC1-Cat6k1#show telnet &lt;br /&gt;
DC1-Cat6k1#show ssh session-info &lt;br /&gt;
DC1-Cat6k1#show conn&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Comments==&lt;br /&gt;
There is a limit of 4 simultaneous TELNET sessions or 4 simultaneous SSH sessions per context at any given time.   &lt;br /&gt;
&lt;br /&gt;
==show running-config== &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE/Admin# sho run&lt;br /&gt;
Generating configuration....&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
login timeout 0&lt;br /&gt;
hostname Pod1-ACE&lt;br /&gt;
&lt;br /&gt;
class-map type management match-any remote-access&lt;br /&gt;
  2 match protocol ssh any&lt;br /&gt;
  3 match protocol snmp any&lt;br /&gt;
  4 match protocol https any&lt;br /&gt;
 &lt;br /&gt;
policy-map type management first-match remote-mgmt&lt;br /&gt;
  class remote-access&lt;br /&gt;
    permit&lt;br /&gt;
&lt;br /&gt;
interface vlan 10&lt;br /&gt;
  description &amp;quot;Client side connectivity&amp;quot;&lt;br /&gt;
  ip address 172.16.1.5 255.255.255.0&lt;br /&gt;
  service-policy input remote-mgmt&lt;br /&gt;
  no shutdown&lt;br /&gt;
&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 172.16.1.1&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Related Information==&lt;br /&gt;
[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp; Documentation - Cisco Systems]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--List links to related information--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Data Center Application Services Configuration Examples]]&lt;/div&gt;</summary>
		<author><name>Pzimmerm</name></author>	</entry>

	</feed>