cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2499
Views
0
Helpful
3
Replies

Access List for blocking External IP

techguy
Level 7
Level 7

Hi,

Can I block external access to my router from telnetting/sshing?  I mean to say if telco gave me public ip address (either via static or dynamic) on my wan port. How can I restrict anyone to access my router by that public ip address. Thanks

3 Replies 3

smitesh kharecha
Level 10
Level 10

Just create a access-list, which only allows known IP address to login to the device and apply it to line vty 0 4.

HTH,

Smitesh

what do you mean by known ip address?. I think it must be a single deny command (explicitly or implicitly) on vty terminals

Hi,

As for emergency situtation (for example, you want to access router, but you are at home) you might want to keep certain IP's allowed rather than blocking everything.

Regards,

Smitesh

Review Cisco Networking for a $25 gift card