Information
The built-in management interface is intended to provide a means to access and manage the switch from anetwork segregated from production traffic. Only stations on the segregated management network can gain management access to the switch. This sharply limits the universe of devices that can attempt unauthorized access.
In the switch software, the management interface is logically separated from the rest of the switch by means of virtual routing and forwarding (VRF); features that are intended to be used on the management interface are assigned to the dedicated mgmt VRF instance. Several management services can be configured to use the mgmt VRF rather than normal switch ports, as illustrated in several examples above.
Traffic cannot be routed between the management interface and normal switch ports, and the management interface can be assigned a dedicated gateway address. The management interface is enabled by default.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
To configure the management interface with a static IP address, gateway, and DNS:
switch(config)# interface mgmt
switch(config-if-mgmt)# ip static 10.1.1.5/24
switch(config-if-mgmt)# default-gateway 10.1.1.1
switch(config-if-mgmt)# nameserver 10.0.1.10 10.0.1.11
To use DHCP instead:
switch(config)# interface mgmt
switch(config-if-mgmt)# ip dhcp
To show the status of the management interface:
switch# show interface mgmt
Address Mode : static
Admin State : up
Mac Address : d0:67:26:11:11:11
IPv4 address/subnet-mask : 10.1.1.5/24
Default gateway IPv4 : 10.1.1.1
IPv6 address/prefix :
IPv6 link local address/prefix : fe80::d267:2611:1111:1111/64
Default gateway IPv6 :
Primary Nameserver : 10.0.1.10
Secondary Nameserver : 10.0.1.11