cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1014
Views
0
Helpful
2
Replies

Cisco 4500x vty access-class

ashley_dew
Level 1
Level 1

Hi,

I have a Cisco 4500x, connected and configured the management interface fa1.

I can ping, telnet, ssh  and so on, and configured the vrf.

I want to restrict access to vty, so I use the default access-class on the vty.

I do that, I lose connections to the cisco 4500x remotely, telnet, ssh does not go through.

Access-list is ok and I can even see the match on the access-list

access-list 120 permit ip host <mypc> <mgt_ip_4500x>

However all connections are blocked.

Can anyone help please.

Thanks

1 Accepted Solution

Accepted Solutions

daniel.dib
Level 7
Level 7

If the interface is in a VRF I think you will need the access-class x in vrf-also command to make it apply to interfaces in VRF as well.

Daniel Dib
CCIE #37149

Please rate helpful posts

Daniel Dib
CCIE #37149
CCDE #20160011

Please rate helpful posts.

View solution in original post

2 Replies 2

daniel.dib
Level 7
Level 7

If the interface is in a VRF I think you will need the access-class x in vrf-also command to make it apply to interfaces in VRF as well.

Daniel Dib
CCIE #37149

Please rate helpful posts

Daniel Dib
CCIE #37149
CCDE #20160011

Please rate helpful posts.

Excellent, it works fine with the vrf-also.

Just to point out works only with standard acl.

Review Cisco Networking for a $25 gift card