Cisco C8300 - Create dedicated Management Interface without OOB Port
Table of Contents
The Cisco C8300 and C8200 routers doesn’t have an Out-of-Band-Management Port. Nevertheless you can create a dedicated management interface over an in-band port.
When using an in-band port for management access it is still going through the normal data plane. When you follow this post, creating an dedicated management port over an in-band port doesn’t make it magically an out-of-band port.
In order to accomplish this we would need to create a dedicated management VRF, assign it to the interface and limit the SSH access with an ACL. The management port can then be connected to the regular out-of-band management network over that port. In the following examples we are using the Gi0/0/0 port as a dedicated management interface.
Creating the VRF & assign interface#
First we create a management VRF.
vrf definition vrf-mgmt
address-family ipv4
exit-address-family
After that we can configure the management port and add it to the VRF.
interface GigabitEthernet0/0/0
description Dedicated Management Port
vrf forwarding vrf-mgmt
ip address 10.0.1.10 255.255.255.0
Lastly we need to add the default route in order to reach the router from other networks.
ip route vrf vrf-mgmt 0.0.0.0 0.0.0.0 10.0.1.1
Restrict Management Access#
Now in order to only allow the management access from the management interface and no other interface, we need create an extended ACL.
ip access-list extended ACL-MGMT
10 permit tcp 192.168.10.0 0.0.0.255 10.0.1.10 eq 22
In the VTY connections the ACL needs to be added but also only allowing ssh connection.
access-class ACL-MGMT in
transport input ssh
Another approach#
A different but sort of same approach is to isolate the user traffic to a dedicated VRF and keep the management addressing inside the global routing.