Configure MGT IP Filters

Before you begin, enable MGT IP Filter in the network policy settings. See Enable MGT IP Filters.

By default, ExtremeCloud IQ devices enable administrative access from all IP addresses. To provide tighter security, you can restrict administrative access. As soon as you apply a filter to a device—which you do by applying the filter to a network policy and then applying that policy to a device—the device denies access from all other IP addresses except those specified in the filter.

Use the following procedure to configure MGT IP Filter objects for use in network policies.

  1. Go to Configure > Common Objects > Security > MGT IP Filters.
  2. Select an existing MGT IP Filter and then select Edit, or select Add.
  3. Type a Name for the policy.
  4. Enter an optional Description.
  5. In the Permitted Management Traffic From section, select an IP address in the Available IP Address column from which you want to permit administrators to access the devices, and then select the single arrow ( > ) to move it to the Selected IP Address column.
  6. Select Add Another IP Object to repeat the process.
  7. Select Save MGT IP Filter.