01-24-2009 08:21 AM - edited 03-06-2019 03:38 AM
Hi,
Is it possible to apply extended ACL to vty lines with specific destination address on Cat6500 12.2(33).
I have noticed that destination address is not effective even though it allows to configure.
01-24-2009 10:55 AM
You are allowing/denying access to the VTY lines.
VTY lines have no IP address so what's the benefit to include the destination?
If you want to allow/deny telnet via some interfaces, you need to implement the ACL on those interfaces (source/destination) if needed.
HTH,
__
Edison.
01-24-2009 12:40 PM
Thanks.
So does it mean, I would need to allow access at two points (in case of allowance). 1) permit source on the vty via access-class 2) permit source on specific destination interface (SVI) on the interface access-list.
Please correct me if I am wrong.
01-24-2009 04:13 PM
Correct.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide