The Cisco C8300 and C8200 routers doesn’t have an Out-of-Band-Management Port. Nevertheless you can create a dedicated management interface over an in-band port.

When using an in-band port for management access it is still going through the normal data plane. When you follow this post, creating an dedicated management port over an in-band port doesn’t make it magically an out-of-band port.

In order to accomplish this we would need to create a dedicated management VRF, assign it to the interface and limit the SSH access with an ACL. The management port can then be connected to the regular out-of-band management network over that port. In the following examples we are using the Gi0/0/0 port as a dedicated management interface.

Creating the VRF & assign interface#

First we create a management VRF.

vrf definition vrf-mgmt
 address-family ipv4
 exit-address-family

After that we can configure the management port and add it to the VRF.

interface GigabitEthernet0/0/0 
 description Dedicated Management Port 
 vrf forwarding vrf-mgmt 
 ip address 10.0.1.10 255.255.255.0 

Lastly we need to add the default route in order to reach the router from other networks.

ip route vrf vrf-mgmt 0.0.0.0 0.0.0.0 10.0.1.1

Restrict Management Access#

Now in order to only allow the management access from the management interface and no other interface, we need create an extended ACL.

ip access-list extended ACL-MGMT
 10 permit tcp 192.168.10.0 0.0.0.255 10.0.1.10 eq 22 

In the VTY connections the ACL needs to be added but also only allowing ssh connection.

access-class ACL-MGMT in 
transport input ssh

Another approach#

A different but sort of same approach is to isolate the user traffic to a dedicated VRF and keep the management addressing inside the global routing.