User manual
Administration services
The following figure shows the Administration Services page:
By default the SnapGear unit runs a web administration server, a Telnet and an SSH
service. Access to these services can be restricted to specific interfaces. Only
Administrative users with the Login access control are able to connect via telnet. SSH
provides for secure encrypted communication whereas telnet is completely unencrypted.
Users connected via the telnet or SSH interfaces have access access to the complete
configuration of the device. SSH is not supported on all devices.
Typically, access to the web management console (Web/SSL Web) is restricted to hosts
on your local network (LAN Interfaces).
Disallowing all services is not recommended as these are the only means by which
configuration changes can be carried out. Thus, no further configuration changes would
be possible and there is no easy way to undo such a change because that requires a
configuration change. There are two ways of recoveriong from this situation as folows:
The easiest way of recovering from this situation is by doing a reset to factory
defaults using the erase button. This causes the loss of all configuration data,
unless it has been saved.
The other way is to perform a recovery boot operation using a netflash.exe (or
tftp/dhcp) with a .sgr recovery boot image, which may then permit access to the
configuration such that normal administrative control can be re-established.
Hower, this method is relatively complex and time-consuming.
136
Firewall