ONTAP Discussions
ONTAP Discussions
In the old 7-mode days, you could create a list of IP addresses on a filer that would restrict administration to someone coming from one of those IP's.
In cluster mode, you can do the same with the SP:
However, I've not found anything to indicate this can be done for regular SSH access or System Manager access. Does anyone know if this type of restriction exists?
Solved! See The Solution
You can define service policies or services firewall policy.
You can define service policies or services firewall policy.
Interesting! Thank you @jcolonfzenpr . I am aware of firewall policies but have never fooled with them.
So essentially I could modify the default "mgmt" policy, which applies to all management LIFs, and change the allow-list to the IP's I want to have access? And that would prevent other IP's from SSH'ing in or accessing via System Manager (assuming I apply to all services)? Am I understanding this right?
Correct. Just modify the firewall and you'll be good to go.
Thank you @paul_stejskal !
