Is it possible to restrict the IP addresses that can connect to ONTAP via HTTPS?
Applies to
- ONTAP 9.6 and later
- HTTPS
- ONTAP System Manager
Answer
Yes, it is possible.
- To restrict HTTPS, use a service policy.
::>set adv -conf off::*>network interface service-policy show::*>network interface service-policy modify-service -vserver <SVM> -policy <policy for management lif> -service management-https -allowed-addresses <ipaddress/netmask>
- Restricting HTTPS allows the followings:
- Restricting the clients that can access ONTAP System Manager.
- Restricting Active IQ Unified Manager that can monitor ONTAP.
- Restricting clients that can execute the REST APIs.
Notes:
- By restricting access, connections from sources other than the allowed clients are blocked.
- If the address range specification is incorrect, clients that need access to ONTAP may also be blocked.
- Carefully specify the clients that require HTTPS access.
