An administrator needs to restrict administrative access to the BIG-IP system so that only specific management workstations can reach the Configuration Utility. Which method is the most secure and appropriate control plane configuration?
The Management IP Allow list specifically restricts administrative access to the BIG-IP GUI and SSH services by source IP address. This provides a robust, built-in control plane firewall mechanism that ensures only authorized administrative subnets can communicate with the system's management services, effectively mitigating unauthorized connection attempts.
Why this answer
Restricting access via the management IP and specific source subnets is critical for hardening the control plane. By utilizing the 'Allow' list under System > Configuration > Device > Management, administrators enforce a network-level security boundary that prevents unauthorized brute-force attempts from reaching the GUI or SSH services. This configuration effectively isolates management traffic from the data plane, ensuring that administrative tasks are performed only from trusted, hardened jump hosts.
Exam trap
Candidates often confuse the 'Allow' list in the Management IP settings with packet filtering via AFM or self-IP packet filters, failing to realize the management interface has its own specific hardening settings.