User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
157
command, option and parameter, without switches or
arguments:
# set idletimeout
<min>
Set the timeout value for all clients (devices on the encrypted
side of the network running the Fortress Secure Client) with:
# set idletimeout
<min>
-c all
Set the timeout value for all hosts (devices in communication
with the Mesh Point on the clear side of the network) with:
# set idletimeout
<min>
-h all
To configure the idle timeout value for a single device, use the
appropriate switch (as shown above:
-c or -h) with the device’s
MAC address, as follows:
# set idletimeout 60 -c 00:09:43:bd:3a:00
The above example sets the idle timeout value for a Secure
Client device with the specified MAC address.
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.6 ACLs and Cleartext Devices
4.6.1 MAC Address Access Control
The Mesh Point supports Access Control List (ACL) filtering of
devices by their MAC (Media Access Control) addresses.
There is also an ACL associated with the Mesh Point’s IPsec
function, which is covered in Section 4.4.5 with the other IPsec
configuration settings.
View the current ACL configuration with
show maclist:
> show maclist
NOTE: The
Max
Blocked
number
is actually the maxi-
mum number of permit-
ted MAC addresses and
show blocked lists
permitted devices by
MAC address.
Filtering Mode: enabled
Mac Address Descriptions MAC Entry Type
----------------- --------------------- -----------------
00:00:00:11:11:13 Test 3 Mesh Point
00:00:00:11:11:14 Test 4 Mesh Point
00:10:60:33:9f:6b Host NMS Mesh Point
00:14:8c:3a:a5:00 automatically added Mesh Point
b4:a4:e3:d1:0a:c3 Router Mesh Point
Total Mac White List entries: 5
View currently blocked devices by MAC address with show
blocked
:
> show blocked
Max Blocked : 200
Blocked Addresses
-----------------
00:14:8c:00:82:00
00:14:8c:12:64:c0