Trusted host configuration is used to prevent unauthorized access to the OLT. The trusted host portion of aaa is configured as follows.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNS9pbWFnZSgxOTIpLnBuZyIsIkNvbmRpdGlvbiI6eyJEYXRlTGVzc1RoYW4iOnsiQVdTOkVwb2NoVGltZSI6MTc2NzIwNTY3Mn19fV19&Signature=Mh~pqaz9RLEKFRo9WeM7gqM78gB6Q0zsFCjC6~IShWox4ea4YtEOshD5zqmthI-aARdTCfpnnJ4eRsdWcGBxyoZm5wICA332sTRig0KY2ErAeNTGXpFatgYZI0hBIsKfXHq8ciuQZ57~Fe7Vk~8ckehkYiuZHcdDVsI2UROELWxA8-5u7F6xzvJOOhY4jS4T3lT6VM-St~GzQEW2la1OGTT50R1Q6rgM~v19t~yzmhD0s9qunoYsV-MFn2Vdyxy9eFRRlZlRNRK9DaNMLmBfitjhiUFeVhrtkn5IaGKSHspRZRue8ORSIW26YcnsRpmTzmJKMMe~7nJduisPR~zQWQ__&Key-Pair-Id=K2TK3EG287XSFC)
System AAA Trusted Host Attributes
| Attribute | Values | Default | Req | Description |
|---|---|---|---|---|
| Interface-name | String | N/A | Y | The interface name to apply the trusted host configuration to. |
| Enable-trusted-host | true | false | false | N | Whether to enable trusted host. Enabling trusted host will block all access from any IP except for those explicitly listed in the configuration. |
| Trusted-hosts | List of strings | N/A | Y |
The EMS must be a part of the list of trusted hosts or the OLT will become unmanageable by the EMS. IP addresses should be used rather than hostnames. |
| Enabled-icmp-destination-unreachable | true | false | true | N |
Whether to send back destination unreachable for unroutable packets. |
| Icmp-rate-limit | 0..1000 | 0 | N |
Rate to limit destination unreachable packets to. Zero indicates that there is no rate limit. |
| Enable-group-icmp-echo-reply | true | false | true | N |
Whether to allow pings to the OLT. Default is ping is blocked. It is more secure not to reply to pings which reveal a targetable IP. |
MDS1-ESUA<Config># tolt system aaa trusted-hosts enable-group-icmp-echo-reply true <enter> MDS1-ESUA<Config># commit <enter> Commit complete. MDS1-ESUA<Config># _ |
MDS1-ESUA(Config)# tolt system aaa trusted-host enable-group-icmp-echo-reply false <enter> MDS1-ESUA(Config)# commit <enter> Commit complete. MDS1-ESUA(Config)# _ |
MDS1-ESUA(<Config># tolt system aaa trusted-hosts trusted-hosts [ 172.28.6.166 10.99.99.110 ] <enter> MDS1-ESUA<Config># tolt system aaa trusted-hosts enable-trusted-host true, <enter> MDS1-ESUA<Config># commit <enter> Commit complete. MDS1-ESUA<Config># _ |
MDS1-ESUA<Config># tolt system aaa trusted-hosts enabled-icmp-destination-unreachable true icmp-rate-limit 2 <enter> MDS1-ESUA<Config># commit <enter> Commit complete. MDS1-ESUA<Config># _ |