Commit d37b382a authored by Leigh B Stoller's avatar Leigh B Stoller

Commit some notes I made a long time ago about creating access control

lists on the genirack control switch, to block access to the ILOs. Would
need to be localized to the rack network of course, and I vaguely
remember that some of the switches had different firmware and so the
commands had to be changed. Also note the netmasks are inverted from
what we normally think they should be. OH HP ...
parent bd8ba4bb
ip access-list extended "IlO"
100 remark "Allow Utah Flux to ILO"
100 permit ip 155.98.60.0 0.0.3.255 155.98.34.3 0.0.0.0
101 permit ip 155.98.60.0 0.0.3.255 155.98.34.21 0.0.0.0
102 permit ip 155.98.60.0 0.0.3.255 155.98.34.22 0.0.0.0
103 permit ip 155.98.60.0 0.0.3.255 155.98.34.23 0.0.0.0
104 permit ip 155.98.60.0 0.0.3.255 155.98.34.24 0.0.0.0
105 permit ip 155.98.60.0 0.0.3.255 155.98.34.25 0.0.0.0
150 remark "Allow Utah Emulab to IlO"
150 permit ip 155.98.32.0 0.0.15.255 155.98.34.3 0.0.0.0
151 permit ip 155.98.32.0 0.0.15.255 155.98.34.21 0.0.0.0
152 permit ip 155.98.32.0 0.0.15.255 155.98.34.22 0.0.0.0
153 permit ip 155.98.32.0 0.0.15.255 155.98.34.23 0.0.0.0
154 permit ip 155.98.32.0 0.0.15.255 155.98.34.24 0.0.0.0
155 permit ip 155.98.32.0 0.0.15.255 155.98.34.25 0.0.0.0
160 remark "Allow Local control node to IlO"
161 permit ip 155.98.34.2 0.0.0.0 155.98.34.3 0.0.0.0
162 permit ip 155.98.34.2 0.0.0.0 155.98.34.21 0.0.0.0
163 permit ip 155.98.34.2 0.0.0.0 155.98.34.22 0.0.0.0
164 permit ip 155.98.34.2 0.0.0.0 155.98.34.23 0.0.0.0
165 permit ip 155.98.34.2 0.0.0.0 155.98.34.24 0.0.0.0
166 permit ip 155.98.34.2 0.0.0.0 155.98.34.25 0.0.0.0
170 remark "Allow Local boss node to IlO"
171 permit ip 155.98.34.4 0.0.0.0 155.98.34.3 0.0.0.0
172 permit ip 155.98.34.4 0.0.0.0 155.98.34.21 0.0.0.0
173 permit ip 155.98.34.4 0.0.0.0 155.98.34.22 0.0.0.0
174 permit ip 155.98.34.4 0.0.0.0 155.98.34.23 0.0.0.0
175 permit ip 155.98.34.4 0.0.0.0 155.98.34.24 0.0.0.0
176 permit ip 155.98.34.4 0.0.0.0 155.98.34.25 0.0.0.0
250 remark "Deny from anywhere else to ILO"
250 deny ip 0.0.0.0 255.255.255.255 155.98.34.3 0.0.0.0
251 deny ip 0.0.0.0 255.255.255.255 155.98.34.21 0.0.0.0
252 deny ip 0.0.0.0 255.255.255.255 155.98.34.22 0.0.0.0
253 deny ip 0.0.0.0 255.255.255.255 155.98.34.23 0.0.0.0
254 deny ip 0.0.0.0 255.255.255.255 155.98.34.24 0.0.0.0
255 deny ip 0.0.0.0 255.255.255.255 155.98.34.25 0.0.0.0
500 remark "Allow all other traffic"
500 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
interface 26 access-group ilo in
write memory
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment