06-14-2021 12:12 AM
Hi,
I have configured some Public loopbacks on my router and when i try to telnet to my router through the Local network it can let me go inside but when i try to telnet router through these Public IP from outside then it is not allowing me. this happens to only one of our /22 subnets. i tried to do on our other subnets and it is working ( from local and from outside).
we do not have any firewall connected to that router and there is no policy on router to block ssh or telnet.
so kindly let me know how can i resolve this issue.
06-14-2021 12:24 AM - edited 06-14-2021 12:39 AM
Hello
It sounds like you either have an access-list negating access, only allowing mgt access on a specific interface (Lan interface) or your public subnets are not being advertsied correctly.
On the device you can check to see if you have any policy negating this access.
sh run | be line
sh access-list
sh management-interface
06-14-2021 12:25 AM
Hello,
can that particular /22 subnet (which is connected on the outside as I understand it) ping the IP address of the outside interface, as well as the IP addresses of the public loopback interfaces ? If possible, post the full running configuration of your router...
06-14-2021 12:31 AM
thanks for the reply,
i can ping the IP from anywhere even from my mobile but just through that particular subnet i am ubable to access my router. with other loopbacks i can access the router from anywhere.
06-14-2021 12:50 AM
Hello @CCIE Aspirant ,
use a looking glass and check the traceroute for each of the public subnets.
Verify if also the subnet that does not allow SSH actually arrives at your router.
If not there is an overlapping with another customer of your ISP.
Hope to help
Giuseppe
06-14-2021 12:56 AM
Thanks for the reply,
all traceroutes coming to our router and it is not overlapping by any other customer.
i have checked all the policy if some can block but it is clear. do i have to ask my ISP or my be open Ticket with RIPE. i dont know what to do.
06-14-2021 12:04 PM
I believe that it would be helpful if we could see the complete config. But as a start can we see the output of show run | begin vty
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide