---
title: "Using the MGMT Port"
canonical: "https://docs.infoblox.com/space/nios85/35417792/Using%20the%20MGMT%20Port"
format: markdown
---
The MGMT (Management) port is a 10/100/1000Base-T Ethernet connector on the front panel of the TE-810, TE-820, TE-1410, TE-1420, TE-2210, TE-2220, and IB-4010 appliances. It allows you to isolate the following types of traffic from other types of traffic on the LAN and HA ports:

> ⚠️ **Note**
> ⚠️ 
> ⚠️ The MGMT port currently does not support DHCP, NAT, or TFTP. IPv6 addressing may be applied to the MGMT port.

Some NIOS appliance deployment scenarios support more than one concurrent use of the MGMT port. The following table depicts MGMT port uses for various appliance configurations.

*Supported* *MGMT* *Port* *Uses* *for* *Various* *appliance* *Configurations*

| **Appliance**** ****Configuration** | **Appliance**** ****Management** | **Grid**** ****Communications** | **DNS**** **** Services** |
| --- | --- | --- | --- |
| Single Independent Appliance | Yes | Not Applicable | Yes |
| Independent HA Pair | Yes | Not Applicable | Active node only |
| Grid Master | Yes | No | Active node only |
| Grid Master Candidate | Yes | No | Active node only |
| HA Grid Member | * | Yes | Active node only |
| Single Grid Member | * | Yes | Yes |

* Although you manage all Grid members through the Grid Master, if you enable the MGMT port on common Grid members, they can send syslog events, SNMP traps, and e-mail notifications, and receive SSH connections on that port.  
Infoblox does not support MGMT port usage for some appliance configurations because it cannot provide redundancy through the use of a VIP. A Grid Master that is an HA pair needs the redundancy that a VIP interface on the HA port provides for Grid communications. Similarly, DNS servers in an HA pair need that redundancy to answer DNS queries. Because the MGMT port does not support a VIP and thus cannot provide redundancy, Grid Masters (and potential Grid Masters) do not support Grid communications on the MGMT port.  
In addition, NIOS appliances in an HA pair support DNS services on the active node only. Only the active node can respond to queries that it receives. If a DNS client sends a query to the MGMT port of the node that happens to be the passive node, the query can eventually time out and fail.  
The MGMT port is not enabled by default. By default, a NIOS appliance uses the LAN port (and HA port when deployed in an HA pair). You must log in using a superuser account to enable and configure the MGMT port. You can configure both IPv4 address and IPv6 address for the MGMT port of a Grid member. You can enable the MGMT port through the Infoblox GUI, as explained in the following sections.

# Appliance Management

You can restrict administrative access to a NIOS appliance by connecting the MGMT port to a subnet containing only management systems. This approach ensures that only appliances on that subnet can access the Infoblox GUI and receive appliance management communications such as syslog events, SNMP traps, and e-mail notifications from the appliance.  
If you are the only administrator, you can connect your management system directly to the MGMT port. If there are several administrators, you can define a small subnet—such as 10.1.1.0/29, which provides six host IP addresses (10.1.1.1–10.1.1.6) plus the network address 10.1.1.0 and the broadcast address 10.1.1.7—and connect to the NIOS appliance through a dedicated switch (which is not connected to the rest of the network). <span style="color: #000000"> The following figure</span> shows how an independent appliance separates appliance management traffic from network protocol services. Note that the LAN port is on a different subnet from the MGMT port.

 *Appliance* *Management* *from* *One* *or* *More* *Management* *Systems*

> Macro (drawio)

  
Similarly, you can restrict management access to a Grid Master to only those appliances connected to the MGMT ports of the active and passive nodes of the Grid Master.  
To enable the MGMT port on an independent appliance or Grid Master for appliance management and then cable the MGMT port directly to your management system or to a network forwarding appliance such as a switch or router:

1. From the **Grid** tab, select the **Grid** **Manager** tab -> **Members** tab -> *Grid_member* checkbox, and then click the Edit icon.
2. In the **Network** -> **Basic** tab of the *Grid* *Member* *Properties* editor, add the MGMT port to the Additional Ports and Addresses table as follows:
3. Click the Add icon and select **MGMT** **(IPv4)** to configure an IPv4 address or select **MGMT** **(IPv6)** to configure an IPv6 address for the MGMT port. You can configure both IPv4 and IPv6 addresses for the MGMT port.  
Grid Manager adds a row for the MGMT port. For an HA pair, it adds two rows, one for each node.
4. Enter the following in the row of the MGMT port for a single Grid Master or independent appliance, and in the rows of the two nodes for an HA Grid Master or independent HA pair:
  - **Interface**: Displays the name of the interface. You cannot modify this.
  - **Address:** Type the IP address for the MGMT port, which must be in a different subnet from that of the LAN and HA ports.
  - **Subnet** **Mask** **(IPv4)** **or** **Prefix** **Length** **(IPv6):** For IPv4 address, specify an appropriate subnet mask for the number of management systems that you want to access the appliance through the MGMT port. For IPv6 address, specify the prefix length.
  - **Gateway:** Type the default gateway for the MGMT port. If you need to define any static routes for traffic originating from the MGMT port—such as SNMP traps, syslog events, and email notifications—destined for remote subnets beyond the immediate subnet, specify the IP address of this gateway in the route.
  - **Port** **Settings:** Choose the connection speed that you want the port to use. You can also choose the duplex setting. Choose **Full** for concurrent bidirectional data transmission or **Half** for data transmission in one direction at a time. Select **Automatic** to instruct the NIOS appliance to negotiate the optimum port connection type (full or half duplex) and speed with the connecting switch automatically. This is the default setting. You cannot configure port settings for vNIOS appliances.
  - **DSCP** **Value**: Displays the Grid DSCP value. To modify, click Override and then enter the DSCP value. You can enter a value from 0 to 63. For information about DSCP, see *[Implementing Quality of Service Using DSCP](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979309)*.
5. In the **Network** -> **Advanced** tab, make sure that the **Enable** **VPN** **on** **MGMT** **Port** checkbox is not selected.
6. Save the configuration and click **Restart** if it appears at the top of the screen.
7. Log out of Grid Manager.
8. Cable the MGMT port to your management system or to a switch or router to which your management system can also connect.
9. If your management system is in a subnet from which it cannot reach the MGMT port, move it to a subnet from which it can.  
The Infoblox Grid Manager GUI is now accessible through the MGMT port on the NIOS appliance from your management system.
10. Open an Internet browser window and enter the IP address of the MGMT port as follows: *https://<IP* *address* *of* *MGMT* *port>*.
11. Log in to Grid Manager.
12. Check the *Detailed* *Status* panel of the Grid member to make sure the status icons are green.

# Grid Communications

You can isolate all Grid communications to a dedicated subnet as follows:

- For Grid communications from the Grid Master, which can be an HA pair or a single appliance, the master uses either the VIP interface on the HA port of its active node (HA master) or its LAN port (single master). Neither a single nor HA Grid Master can use its MGMT port for Grid communications. (This restriction applies equally to Master Candidates.)
- Common Grid members connect to the Grid Master through their MGMT port.

This ensures that all database synchronization and Grid maintenance operations are inaccessible from other network elements while the common Grid members provide network protocol services on their LAN ports.

The following figure shows how Grid members communicate to the master over a dedicated subnet.  
*Grid* *Communications*

> Macro (drawio)

## Enabling Grid Communications over the MGMT Port for Existing Grid Members

To enable the MGMT port for Grid communications on an existing single or HA Grid member:

> ⚠️ **Note**
> ⚠️ 
> ⚠️ You must enable the MGMT port before modifying its port settings.

1. Log in to the Grid Master with a superuser account.
2. From the **Grid** tab, select the **Grid** **Manager** tab -> **Members** tab -> *Grid_member* checkbox, and then click the Edit icon.
3. In the **Network** -> **Basic** tab of the *Grid* *Member* *Properties* editor, add the MGMT port to the Additional Ports and Addresses table as follows:
4. Click the Add icon and select **MGMT** **(IPv4)** to configure an IPv4 address or select **MGMT** **(IPv6)** to configure an IPv6 address for the MGMT port. You can configure both IPv4 address and IPv6 address for the MGMT port.  
Grid Manager adds a row for the MGMT port. For an HA pair, it adds two rows, one for each node.
5. Enter the following in the row of the MGMT port for a single Grid Master or independent appliance, and in the rows of the two nodes for an HA Grid Master or independent HA pair:
  - **Interface**: Displays the name of the interface. You cannot modify this.
  - **Address:** Type the IP address for the MGMT port, which must be in a different subnet from that of the LAN and HA ports.
  - **Subnet** **Mask** **(IPv4)** **or** **Prefix** **Length** **(IPv6):** For IPv4 address, specify an appropriate subnet mask for the number of management systems that you want to access the appliance through the MGMT port. For IPv6 address, specify the prefix length.
  - **Gateway:** Type the default gateway for the MGMT port. If you need to define any static routes for traffic originating from the MGMT port—such as SNMP traps, syslog events, and email notifications—destined for remote subnets beyond the immediate subnet, specify the IP address of this gateway in the route.
  - **Port** **Settings:** Choose the connection speed that you want the port to use. You can also choose the duplex setting. Choose **Full** for concurrent bidirectional data transmission or **Half** for data transmission in one direction at a time. Select **Automatic** to instruct the NIOS appliance to negotiate the optimum port connection type (full or half duplex) and speed with the connecting switch automatically. This is the default setting. You cannot configure port settings for vNIOS appliances.
  - **DSCP** **Value**: Displays the Grid DSCP value. To modify, click **Override** and enter the DSCP value. You can enter a value from 0 to 63. For information about DSCP, see *[Implementing Quality of Service Using DSCP](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979309)*.  
[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979309/Configuring+Ethernet+Ports#ConfiguringEthernetPorts-bookmark901)
6. In the **Network** -> **Advanced** tab, select the **Enable** **VPN** **on** **MGMT** **Port** checkbox.
7. In the **Security** tab, do the following:
  - **Restrict** **Remote** **Console** **and** **Support** **Access** **to** **MGMT** **Port:** Select this checkbox to restrict SSH (Secure Shell) v2 access to the MGMT port only. This restricts Infoblox Technical Support and remote console connections—both of which use SSH v2—to just the MGMT port. For an HA pair, you can make an SSH v2 connection to the MGMT port on both the active and passive nodes.  
Clear the checkbox to allow SSH v2 access to both the MGMT and LAN ports. For an HA pair, you can make an SSH v2 connection to the MGMT and LAN ports on both the active and passive nodes.
8. Save the configuration and click **Restart** if it appears at the top of the screen.  
The master communicates the new port settings to the member, which immediately begins using them. The member stops using its LAN port for Grid communications and begins using the MGMT port.
9. To confirm that the member still has Grid connectivity, check that the status icons for that member are green on the *Detailed* *Status* and *Grid* panels.

# DNS Services

You can configure a single independent appliance or single Grid member to provide DNS services through the MGMT port in addition to the LAN port. For example, the appliance can provide DNS services through the MGMT port for internal clients on a private network, and DNS services through the LAN port for external clients on a public network.  
While providing DNS services on the MGMT port, you can still use that port simultaneously for appliance management. The following figure shows a management system communicating with a single independent appliance through its MGMT port while the appliance also provides DNS services on that port to a private network. Additionally, the appliance provides DNS services to an external network through its LAN port.   
  
*DNS* *Services* *on* *the* *LAN* *and* *MGMT* *Ports,* *and* *appliance* *Management* *on* *the* *MGMT* *Port*   


> Macro (drawio)

  
  
Like a single independent appliance, a single Grid member can also support concurrent DNS traffic on its MGMT and LAN ports. However, because you manage all Grid members through the Grid Master, a Grid member only uses an enabled MGMT port to send SNMP traps, syslog events, and email notifications, and to receive SSH connections.  
In addition, the active node of an HA pair can provide DNS services through its MGMT port. To use this feature, you must enable DNS services on the MGMT ports of both nodes in the HA pair and specify the MGMT port IP addresses of both nodes on the DNS client as well, in case there is a failover and the passive node becomes active. Note that only the active node can respond to queries that it receives. If a DNS client sends a query to the MGMT port of the node that happens to be the passive node, the query can eventually time out and fail.  
To enable DNS services on the MGMT port of an appliance:

1. From the **Grid** tab, select the **Grid** **Manager** tab -> **Members** tab -> *Grid_member* checkbox, and then click the Edit icon.  
Note that:
  - You must enable the MGMT port before modifying its port settings. See Using the MGMT Port.
  - You must mandatorily configure the LAN interface before joining the HA nodes to the Grid. If you join the nodes with VLAN tagging already enabled on HA, the new nodes must join with VLAN tagging only. If you join the nodes using the MGMT interface, you must enable VLAN tagging for the new nodes.
2. In the **Network** -> **Basic** tab of the *Grid* *Member* *Properties* editor, add the MGMT port to the *Additional Ports and Addresses* table as follows:
  1. Click the Add icon and select **MGMT** **(IPv4)** to configure an IPv4 address or select **MGMT** **(IPv6)** to configure an IPv6 address for the MGMT port. You can configure both IPv4 and IPv6 address for the MGMT port.  
Grid Manager adds a row for the MGMT port. For an HA pair, it adds two rows, one for each node.
  2. Enter the following in the row of the MGMT port for a single Grid Master or independent appliance, and in the rows of the two nodes for an HA Grid Master or independent HA pair:
    - **Interface**: Displays the name of the interface. You cannot modify this.
    - **Address:** Type the IP address for the MGMT port, which must be in a different subnet from that of the LAN and HA ports.
    - **Subnet** ** Mask** ** (IPv4) ** **or ** **Prefix ** **Length ** **(IPv6):** For IPv4 address, specify an appropriate subnet mask for the number of management systems that you want to access the appliance through the MGMT port. For IPv6 address, specify the prefix length.
    - **Gateway:** Type the default gateway for the MGMT port. If you need to define any static routes for traffic originating from the MGMT port—such as SNMP traps, syslog events, and email notifications—destined for remote subnets beyond the immediate subnet, specify the IP address of this gateway in the route.
    - **Port** ** Settings:** Choose the connection speed that you want the port to use. You can also choose the duplex setting. Choose **Full** for concurrent bidirectional data transmission or **Half** for data transmission in one direction at a time. Select **Automatic** to instruct the NIOS appliance to negotiate the optimum port connection type (full or half duplex) and speed with the connecting switch automatically. This is the default setting. You cannot configure port settings for vNIOS appliances.
    - **DSCP** ** Value**: Displays the Grid DSCP value. To modify, click **Override** and enter the DSCP value. You can enter a value from 0 to 63. For information about DSCP, see *[Implementing Quality of Service Using DSCP](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35979309)*.
  3. Click **Save** **&** **Close** to save your settings for the MGMT port.
3. From the **Data** **Management** tab, select the **DNS** tab -> -> **Members** tab -> *Grid_member* checkbox, and then click the Edit icon.
4. In the **General** -> **Basic** tab of the *Member* *DNS* *Properties* editor, do the following:
  - If you are running DNS service for IPv4, select the IPv4 checkbox for **MGMT** under **DNS** **Interfaces**.
  - If you are running DNS service for IPv6, select the IPv6 checkbox for **MGMT** under **DNS** **Interfaces**.
5. In the **General** -> **Advanced** tab, select one of the following from the **Send** **queries** **from** and the **Send** **notify** **messages** **and** **zone** **transfer** **requests** **from** drop-down lists:
  - **VIP**: The appliance uses the IP address of the HA port as the source for queries, notifies, and zone transfer requests.
  - **MGMT**: The appliance uses the IP address of the MGMT port as the source for queries, notifies, and zone transfer requests.
  - **LAN2:** The appliance uses the IP address of the LAN2 port as the source for queries, notifies, and zone transfer requests.
  - **Any**: The appliance chooses which port to use as the source for queries, notifies, and zone transfer requests.  
The **Send** **queries** **from** drop-down list also includes loopback IP addresses that you configured. You can select a loopback address as the source for queries.
6. Save the configuration and click **Restart** if it appears at the top of the screen.

To see that the appliance now also serves DNS on the MGMT port:

1. From the **Data** **Management** tab, select the **DNS** tab -> -> **Members** tab -> *Grid_member* checkbox.
2. Expand the Toolbar and click **View** -> **View** **DNS** **Configuration**.
3. Check that the IP address of the MGMT port appears in the address match list in the listen-on substatement.