<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disable Telnet on Outside Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730320#M553607</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Manish, thanks again.&amp;nbsp; I applied the configs as instructed (below), but can still telnet to the public IP from outside the network.&amp;nbsp; Is there a command that is allowing telnet to the outside interface that supercedes these configs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended TerminalAccess &lt;BR /&gt;permit tcp host 172.16.0.0 any eq telnet &lt;BR /&gt;permit tcp any any eq 22 &lt;BR /&gt;deny tcp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4 &lt;BR /&gt;access-class TerminalAccess in&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jun 2011 20:29:43 GMT</pubDate>
    <dc:creator>pccareoncall</dc:creator>
    <dc:date>2011-06-15T20:29:43Z</dc:date>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730313#M553591</link>
      <description>&lt;P&gt;Hello, I am using a Cisco 2801 Router and currently have Telnet enabled on all interfaces.&amp;nbsp; How do I change that so it is enabled from all inside networks, but not on the outside interface?&amp;nbsp; Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what I can find in the configs regarding Telnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;privilege level 15&lt;/P&gt;&lt;P&gt;password XXXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;transport input telnet ssh&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730313#M553591</guid>
      <dc:creator>pccareoncall</dc:creator>
      <dc:date>2019-03-11T20:45:40Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730314#M553595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use access-list + access-class under line vty to limit the subnets allowed to telnet/ssh the router. &lt;/P&gt;&lt;P&gt;Please look in the example mention in the following link ( PDF) :- &lt;/P&gt;&lt;P&gt;&lt;CITE&gt;&lt;A class="jive-link-external-small" href="https://learningnetwork"&gt;https://learningnetwork&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;STRONG&gt;cisco&lt;/STRONG&gt;.com/.../8%20steps%20to%20secure%20and%20harden%20&lt;STRONG&gt;Cisco&lt;/STRONG&gt;%20Router.pdf&lt;/CITE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 18:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730314#M553595</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-06-15T18:33:25Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730315#M553597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"transport input" command will impact all interface. For example, if you use "transport input ssh", user can only access this router via SSH. Per your scenario, you can just configure a interface ACL on outside interface to block the telnet session. HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 18:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730315#M553597</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2011-06-15T18:34:22Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730316#M553599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Manish, thanks for your response.&amp;nbsp; However, that link was broken and I am unable to locate that document.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 18:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730316#M553599</guid>
      <dc:creator>pccareoncall</dc:creator>
      <dc:date>2011-06-15T18:35:58Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730317#M553601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yudong,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp; What would this ACL command look like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 18:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730317#M553601</guid>
      <dc:creator>pccareoncall</dc:creator>
      <dc:date>2011-06-15T18:37:01Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730318#M553604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try this :- &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://blog.ioshints.info/2006/12/vty-access-class-accepts-extended-and.html"&gt;http://blog.ioshints.info/2006/12/vty-access-class-accepts-extended-and.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 19:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730318#M553604</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-06-15T19:11:05Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730319#M553606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It will depend on how you would like to control telnet.&lt;/P&gt;&lt;P&gt;If you don't want any telnet session come into outside interface (including telnet session passing throught this box), you can configure like the below&lt;/P&gt;&lt;P&gt;ip access-list ex no_telnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; deny tcp any any eq telnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; permit &lt;ANY other="" traffic="" which="" neeed="" to="" be="" allowed=""&gt;&lt;/ANY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't want any one to telnet to outside interface IP directly, you can configure like the folowing&lt;/P&gt;&lt;P&gt;ip access-list ex no_telnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; deny tcp any host &lt;OUTSIDE_INTERFACE_IP&gt; eq telnet&lt;/OUTSIDE_INTERFACE_IP&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; permit &lt;ANY other="" traffic="" which="" neeed="" to="" be="" allowed=""&gt;&lt;/ANY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can apply this ACL under the outside interface in inbound direction.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 19:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730319#M553606</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2011-06-15T19:11:08Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730320#M553607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Manish, thanks again.&amp;nbsp; I applied the configs as instructed (below), but can still telnet to the public IP from outside the network.&amp;nbsp; Is there a command that is allowing telnet to the outside interface that supercedes these configs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended TerminalAccess &lt;BR /&gt;permit tcp host 172.16.0.0 any eq telnet &lt;BR /&gt;permit tcp any any eq 22 &lt;BR /&gt;deny tcp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4 &lt;BR /&gt;access-class TerminalAccess in&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 20:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730320#M553607</guid>
      <dc:creator>pccareoncall</dc:creator>
      <dc:date>2011-06-15T20:29:43Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730321#M553609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, That didn't work for as you were using Named ACL , when applying access control to a Line&amp;nbsp; , you are required to use a numbered ACL ( Kinda dumb but it is what it is &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ). &lt;/P&gt;&lt;P&gt;So, make it a stardard acl using no and then apply it to the Line VTY. &lt;/P&gt;&lt;P&gt;Reference :- &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_2/ip/configuration/guide/1cfip.html#wp1001490"&gt;http://www.cisco.com/en/US/docs/ios/12_2/ip/configuration/guide/1cfip.html#wp1001490&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 20:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730321#M553609</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-06-15T20:44:27Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730322#M553611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not want telnet allowed to the outside interface at all, but we do have email services, etc. allowed through NAT commands.&amp;nbsp; Would I need to permit those in this new "no_telnet" access list, or will those still be allowed with the existing configs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 20:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730322#M553611</guid>
      <dc:creator>pccareoncall</dc:creator>
      <dc:date>2011-06-15T20:45:58Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730323#M553613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; What would this standard ACL config look like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 21:07:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730323#M553613</guid>
      <dc:creator>pccareoncall</dc:creator>
      <dc:date>2011-06-15T21:07:47Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730324#M553615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use :- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 12 permit host 172.16.x.x ( one host address in that subnet )&lt;/P&gt;&lt;P&gt;access-list 12 permit host X.X.X.X&amp;nbsp; ( any other ip that you need whitelisted )&lt;/P&gt;&lt;P&gt;access-list 12 permit 172.16.0.0 0.0.255.255 ( complete 172.16.0.0/16 subnet access ok )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Line vty 0 4&lt;/P&gt;&lt;P&gt;access-class 12 in &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind that This will limit connections to the Line&amp;nbsp; be it for SSH or Telnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never used Extended ACL in access-class and donot have any equipment to test it either. So, if you want to use your above extendent acl , you can try by replacing name "TerminalAccess" with a no. like 199 or 200. But be sure that you have console access to the device in case you lock your self out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2011 21:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730324#M553615</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-06-15T21:30:37Z</dc:date>
    </item>
    <item>
      <title>Disable Telnet on Outside Interface</title>
      <link>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730325#M553617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, there is no need for such access-list, because you deny telnet only on vty lines, that are used only for remote management, not for connectivity and routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 05:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-telnet-on-outside-interface/m-p/1730325#M553617</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2011-06-16T05:38:23Z</dc:date>
    </item>
  </channel>
</rss>

