User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
117
Client management is enabled (on) by default.
If encrypted interface client management is disabled (
off), you
will be able to manage the Mesh Point only through a clear
interface (or through the serial Console port).
Enable/disable client management access on the Mesh Point’s
encrypted interfaces with the
set command:
# set clientmanagement on|off
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.10.2 Authorized Cleartext Device Management Access
NOTE:
If either
clientmanage-
ment or cleartext
is
off
, clear devices on
encrypted interfaces will
not be able to manage
the Mesh Point, regard-
less of the
clearman-
agement
setting.
By default, the Mesh Point blocks management access by
authorized cleartext devices on encrypted interfaces. View the
current setting with the
show command:
> show clearmanagement
Off
If management access via encrypted interfaces is globally
permitted (see
clientmanagement, above), you can enable
management access for authorized cleartext devices on
encrypted interfaces with the
set command:
# set clearmanagement on|off
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.11 Authorized Wireless Client Management
Settings
By default, the Mesh Point allows management access by
authorized wireless clients in the clear zone. View the current
setting with the show command:
> show wifimanagement
On
The management access for authorized wireless clients in the
clear zone can be configured with the set command:
# set wifimanagement on|off
You mut be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.12 Turning Mesh Point GUI Access Off and On
Browser connections to the Mesh Point’s management
interface are secured via https (Hypertext Transfer Protocol
Secure). GUI access can be authenticated via the self-signed
X.509 digital certificate automatically generated by the Mesh
Point for use by SSL (Secure Socket Layer) and present by
default in the local certificate store. You can also import and
select a different certificate for the Mesh Point's SSL function
(refer to Section 4.2.2).