メインコンテンツへスキップ

SSHアクセスを特定のIPアドレスに制限する方法

Views:
243
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core
Last Updated:
pandar

色の定義

Color_Def.png

環境

ONTAP 9

概要

アクセスはサービスポリシー(LIFごと、SVMごと)によって決定され、IPアドレスによるSSHへの特定のアクセスを提供する特定のポリシーを適用する方法を示します

手順

  1. SVMとそのサービスに割り当てられているサービスポリシーを確認します:

::> network interface show -vserver svm1 -fields service-policy, services​​​​​​vserver    lif                    service-policy       services-------    ------------------     ----------------     --------------------------------------------------------svm1       svm1_cifs_nfs_lif1     custom-data-1234     data-core,data-nfs,data-cifs,management-ssh,management- https

 

::> network interface service-policy show -vserver svm1 -policy custom-data-1234
Vserver: svm1
Policy Name: custom-data-1234
Included Services: data-core, data-nfs, data-cifs, management-ssh,
management- https
Service: Allowed Addresses: data-core: 0.0.0.0/0
data-nfs: 0.0.0.0/0
data-cifs: 0.0.0.0/0
management-ssh: 0.0.0.0/0
management- https: 0.0.0.0/0
  1. 詳細モードで、適切な SVM および LIF の management-sshサービスを変更して、必要な IP のみを許可します:
::*> set advanced
Warning: These advanced commands are potentially dangerous; use them only when directed to do so by NetApp
personnel.
Do you want to continue? {y|n}: y
 
::*> network interface service-policy modify-service -vserver svm1 -policy custom-data-1234 -service management-ssh -allowed-addresses 10.10.10.0/24
 
ヒント:アクセスを少数の単一の IP のみに制限するには、/32 サブネットマスクを使用し、IP をコンマで区切ります:
cluster1::*> network interface service-policy modify-service -vserver svm1 -policy custom-data-1234 -service management-ssh -allowed-addresses 10.10.10.10/32,10.10.10.30/32
 
  1. service-policy 変更内容を確認します:
::*> network interface service-policy show -vserver svm1 -policy custom-data-1234
 
Vserver: svm1
Policy Name: custom-data-3499
Included Services: data-core, data-nfs, data-cifs, management-ssh,
management-https
Service: Allowed Addresses: data-core: 0.0.0.0/0
data-nfs: 0.0.0.0/0
data-cifs: 0.0.0.0/0
management-ssh: 10.10.10.0/24
management-https: 0.0.0.0/0
Is Built-In Policy: false

パートナーノート

partnerNotes_text
 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.