mVLAN
To use a remote network management system (NMS) to manage devices in a centralized manner, configure a management IP address on the switch. You can then use the management IP address to log in to the switch using STelnet and manage the switch. If a user-side interface is added to the VLAN corresponding to the management IP address, users connected to the interface can also log in to the switch. This poses security risks to the switch.
To enhance security, you can configure the VLAN as a management VLAN (mVLAN). Do not permit Access or Dot1q tunnel interfaces to be added to the mVLAN as they are often connected to users. When these interfaces are prevented from joining the mVLAN, users connected to the interfaces cannot log in to the device, improving device security.