<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: disabling telnet access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799802#M419787</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pq,&lt;/P&gt;&lt;P&gt;Well this is due to CAT OS architecture. It will show that telnet port is open but no one will be able to telnet until you define ip permit list for telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no ip permit list is there, telnet is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Aug 2007 15:17:37 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2007-08-24T15:17:37Z</dc:date>
    <item>
      <title>disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799791#M419763</link>
      <description>&lt;P&gt;I have disabled telnet access to my Cisco2948 and Cisco5609 (runing CATOS) but im still able to telnet, am i missing anything? here is my config&lt;/P&gt;&lt;P&gt;set ip permit enable ssh&lt;/P&gt;&lt;P&gt;set ip permit enable snmp&lt;/P&gt;&lt;P&gt;set ip permit 10.0.0.0 255.0.0.0 ssh&lt;/P&gt;&lt;P&gt;set ip permit 10.0.0.0 255.0.0.0 snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; sh ip permit&lt;/P&gt;&lt;P&gt;   Telnet permit list disabled.&lt;/P&gt;&lt;P&gt;   Ssh permit list enabled.&lt;/P&gt;&lt;P&gt;   Snmp permit list enabled.&lt;/P&gt;&lt;P&gt;Permit List        Mask               Access-Type &lt;/P&gt;&lt;P&gt;----------------   ----------------   -------------&lt;/P&gt;&lt;P&gt;10.0.0.0           255.0.0.0          ssh snmp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799791#M419763</guid>
      <dc:creator>nawas</dc:creator>
      <dc:date>2019-03-26T00:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799792#M419765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have already tried,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set ip permit disable telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then something seems to be not correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share sh ver?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2007 19:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799792#M419765</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-08-17T19:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799793#M419767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I did "set ip permit disable telnet " that's why it shows "telnet disabled" in show ip permit. Here is the show ver &lt;/P&gt;&lt;P&gt;From 6509:---------&lt;/P&gt;&lt;P&gt;sh ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: This product contains cryptographic features and is subject to United&lt;/P&gt;&lt;P&gt;States and local country laws governing import, export, transfer and use.&lt;/P&gt;&lt;P&gt;Delivery of Cisco cryptographic products does not imply third-party authority&lt;/P&gt;&lt;P&gt;to import, export, distribute or use encryption. Importers, exporters,&lt;/P&gt;&lt;P&gt;distributors and users are responsible for compliance with U.S. and local&lt;/P&gt;&lt;P&gt;country laws. By using this product you agree to comply with applicable&lt;/P&gt;&lt;P&gt;laws and regulations. If you are unable to comply with U.S. and local laws,&lt;/P&gt;&lt;P&gt;return this product immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WS-C6506 Software, Version NmpSW: 8.5(2)&lt;/P&gt;&lt;P&gt;Copyright (c) 1995-2005 by Cisco Systems&lt;/P&gt;&lt;P&gt;NMP S/W compiled on Dec  6 2005, 21:05:19&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System Bootstrap Version: 7.7(1)&lt;/P&gt;&lt;P&gt;System Web Interface Version: Engine Version: 5.3.4 ADP Device: Cat6000 ADP Version: 8.0 ADK: 49&lt;/P&gt;&lt;P&gt;System Boot Image File is 'bootflash:cat6000-sup720cvk9.8-5-2.bin'&lt;/P&gt;&lt;P&gt;System Configuration register is 0x10f&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From 4006:----&lt;/P&gt;&lt;P&gt;sh ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: This product contains cryptographic features and is subject to United&lt;/P&gt;&lt;P&gt;States and local country laws governing import, export, transfer and use.&lt;/P&gt;&lt;P&gt;Delivery of Cisco cryptographic products does not imply third-party authority&lt;/P&gt;&lt;P&gt;to import, export, distribute or use encryption. Importers, exporters,&lt;/P&gt;&lt;P&gt;distributors and users are responsible for compliance with U.S. and local&lt;/P&gt;&lt;P&gt;country laws. By using this product you agree to comply with applicable&lt;/P&gt;&lt;P&gt;laws and regulations. If you are unable to comply with U.S. and local laws,&lt;/P&gt;&lt;P&gt;return this product immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WS-C4006 Software, Version NmpSW: 8.1(2)&lt;/P&gt;&lt;P&gt;Copyright (c) 1995-2003 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From 2948:-&lt;/P&gt;&lt;P&gt;sh ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: This product contains cryptographic features and is subject to United&lt;/P&gt;&lt;P&gt;States and local country laws governing import, export, transfer and use.&lt;/P&gt;&lt;P&gt;Delivery of Cisco cryptographic products does not imply third-party authority&lt;/P&gt;&lt;P&gt;to import, export, distribute or use encryption. Importers, exporters,&lt;/P&gt;&lt;P&gt;distributors and users are responsible for compliance with U.S. and local&lt;/P&gt;&lt;P&gt;country laws. By using this product you agree to comply with applicable&lt;/P&gt;&lt;P&gt;laws and regulations. If you are unable to comply with U.S. and local laws,&lt;/P&gt;&lt;P&gt;return this product immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WS-C2948 Software, Version NmpSW: 8.4(9)GLX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2007 19:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799793#M419767</guid>
      <dc:creator>nawas</dc:creator>
      <dc:date>2007-08-17T19:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799794#M419770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well I was not able to find anything on these versions to be specific. I wasn?t able to find anything wrong though, the way you have it setup. Until someone else can point us out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you want you can get this thing to be investigated by TAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2007 23:01:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799794#M419770</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-08-17T23:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799795#M419772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nawas,&lt;/P&gt;&lt;P&gt;This is how it works,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ip permit disable telnet---&amp;gt; Disables the use of a permit list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to enable the permit list and then define which IP addresses are allowed to&lt;/P&gt;&lt;P&gt;telnet to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no IPs are defined then no telnet is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to disable telnet you need to enable it using---&amp;gt; Ip permit enable telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now do not define any IP address for telnet. That way no one would be able to telnet to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also to limit telnet access on the CAT OS you need to define who is permitted to telnet to&lt;/P&gt;&lt;P&gt;the device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eg,  &lt;/P&gt;&lt;P&gt;set ip permit &lt;HOST ip="" address=""&gt; telnet&lt;/HOST&gt;&lt;/P&gt;&lt;P&gt;set ip permit &lt;HOST ip="" address=""&gt; telnet&lt;/HOST&gt;&lt;/P&gt;&lt;P&gt;set ip permit &lt;HOST ip="" address=""&gt; telnet&lt;/HOST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This creates a permit list. Once you do this you can enable the list to be processed by&lt;/P&gt;&lt;P&gt;the switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set ip permit enable telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This tells the switch to only allow telnet for IP addresses defined in the permit list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2007 11:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799795#M419772</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-08-18T11:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799796#M419774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JG is right,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unconventional, but this is how it works!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@JG : Great work TSing &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2007 11:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799796#M419774</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-08-19T11:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799797#M419775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is exactly I have configured my devices but still have no luck. To  note that I had telnet enabled at some point now I want to disable telnet. I even tried ripping the whole permit list configureation and disabling permit list and enabling it but still no luck. Guess I will have to open a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2007 12:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799797#M419775</guid>
      <dc:creator>nawas</dc:creator>
      <dc:date>2007-08-20T12:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799798#M419777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Nawas,&lt;/P&gt;&lt;P&gt;Please mark this thread resolved , so other can benefit from it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2007 20:05:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799798#M419777</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-08-20T20:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799799#M419778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you opened a TAC case? What is the resolution if you don't mind to share?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;pq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 14:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799799#M419778</guid>
      <dc:creator>pdquan001</dc:creator>
      <dc:date>2007-08-24T14:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799800#M419780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pq,&lt;/P&gt;&lt;P&gt;That issue has been fixed. Here is the solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is how it works,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ip permit disable telnet---&amp;gt; Disables the use of a permit list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to enable the permit list and then define which IP addresses are allowed to&lt;/P&gt;&lt;P&gt;telnet to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no IPs are defined then no telnet is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to disable telnet you need to enable it using---&amp;gt; Ip permit enable telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now do not define any IP address for telnet. That way no one would be able to telnet to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also to limit telnet access on the CAT OS you need to define who is permitted to telnet to&lt;/P&gt;&lt;P&gt;the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eg,&lt;/P&gt;&lt;P&gt;set ip permit &lt;HOST ip="" address=""&gt; telnet&lt;/HOST&gt;&lt;/P&gt;&lt;P&gt;set ip permit &lt;HOST ip="" address=""&gt; telnet&lt;/HOST&gt;&lt;/P&gt;&lt;P&gt;set ip permit &lt;HOST ip="" address=""&gt; telnet&lt;/HOST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This creates a permit list. Once you do this you can enable the list to be processed by&lt;/P&gt;&lt;P&gt;the switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set ip permit enable telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This tells the switch to only allow telnet for IP addresses defined in the permit list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 14:55:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799800#M419780</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-08-24T14:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799801#M419783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks JG.&lt;/P&gt;&lt;P&gt;But the problem I have is that when IT Security people perform the network scan, it still shows that telnet service is enable. In another word, port 23 is still open. Is there a way to shutdown the telnet service totally?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 15:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799801#M419783</guid>
      <dc:creator>pdquan001</dc:creator>
      <dc:date>2007-08-24T15:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: disabling telnet access</title>
      <link>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799802#M419787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pq,&lt;/P&gt;&lt;P&gt;Well this is due to CAT OS architecture. It will show that telnet port is open but no one will be able to telnet until you define ip permit list for telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no ip permit list is there, telnet is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 15:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/disabling-telnet-access/m-p/799802#M419787</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-08-24T15:17:37Z</dc:date>
    </item>
  </channel>
</rss>

