A global policy for management and service plane protection can be applied to the entire device to filter packets of certain types.
The system view is displayed.
A global policy for management and service plane protection is created.
A rule about whether to send the packets of specified protocols to the CPU is configured in the global policy.
If FTP, SSH, SNMP, TFTP, or TELNET is disabled globally by running the protocol command and is not enabled on any active interface, connectivity to the device will be interrupted. (An active interface is an interface that can properly receive and send packets.)
To ensure connectivity to the device, configure additional active interfaces and enable these protocols on them.
The global policy is enabled.
The configuration is committed.