NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Alain_Sanchez
Feb 13, 2023Aspirant
Disable in-band management on M4300-28G
I want to disable any in-band management possibility on my M4300-28G and leave only OOB management.
Currently I'm using the switch as a router and set the management vlan to 999 which is a vlan that does not have a valid IP address, and despite that, Managemnet Web GUI, telnet, and ssh are accesible from every vlan on the switch that has an IP address... don't understand why.
9 Replies
- schumakuGuru - Experienced User
This is the intended default behavior for the in-band management..
The in-band CPU management access can be disabled, limiting the access to the the switch CPU for GUI, telnet etc. via the OOB service port if you have a separate management network. Further on you can deploy Management ACLs for protecting inband access (for instance, restricting HTTP GUI access to certain IP addresses or subnets, restricting Telnet to certain other IP addresses, etc.).
- Alain_SanchezAspirant
How can I disable in-band CPU management access? I have Management Source Interface set to Service Port yet I still have in-band access to management.
Also, I don't understand why I can access switch management from every single vlan of the switch with an IP address if I explicitly selected a Managenment VLAN. What's the point of having an in-band management vlan if I can access the switch from every vlan with routing enabled?
- schumakuGuru - Experienced User
Alain_Sanchez wrote:
How can I disable in-band CPU management access?
These are no consumer class devices with simple on-off controls for many reasons.
Alain_Sanchez wrote:
I have Management Source Interface set to Service Port yet I still have in-band access to management.
Well, you have enabled OOB, this does not imply any in-band vectors will be disabled.
Alain_Sanchez wrote:
Also, I don't understand why I can access switch management from every single vlan of the switch with an IP address if I explicitly selected a Managenment VLAN.
A kind of an industry standard on business switches and routers.
Alain_Sanchez wrote:
What's the point of having an in-band management vlan if I can access the switch from every vlan with routing enabled?
In-band and out-of-band is fully concurrent.
Put up access controls for all vectors you want to allow or deny.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!