Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (2024)

Remote access via virtual terminal or virtual tty (vty) lines can also be secured by configuring inbound and outbound Access Control Lists (ACLs). Inbound ACLs enable inbound connections to a Cisco device, router or switch, from a restricted list of IP addresses. On the other hand, outbound ACLs controls outbound access from Cisco devices. The best practice is to allow internal or trusted network IP addresses to access the vty lines.

ACL Configuration on VTY Lines

To configure standard or extended ACL on a vty line, we use the ‘access-class {access-list-number|access-list-name} {in|out}‘ configuration commands. We enter the command under the vty line configuration mode.

For our example, we have routers R1, R2, and R3 here. We want R1 to allow connections with R2 but not with R3.Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (1)

First, we have to create our access lists on R1’s global configuration mode. We will have two standard access lists, one to permit R2 at 192.168.1.10 and one to block R3 with an IP address of 192.168.2.10 for this example. We will use the access list number 1. Enter the following commands:

R1(config)#access-list 1 permit 192.168.1.10R1(config)#access-list 1 deny 192.168.2.10

Then, we will apply the ACL we’ve created to the vty lines to permit Telnet or SSH traffic. We will use the ‘access-class’ command under the vty line configuration mode. We have to specify the access list number, which is 1, and we will use the keyword ‘in’ for inbound ACL. This is to control inbound Telnet connections. Enter configuration commands one per line:

R1(config)#line vty 0 4R1(config-line)#access-class 1 inR1(config-line)# exit

Verifying ACL Access on VTY Lines

To view the configurations under the vty lines, we can use the ‘show running-config | section line vty’ command.

R1# show running-config | section line vtyline vty 0 4access-class 1 inlogin local

To check our vty connectivity, we can use Telnet or SSH (Secure Shell). In our example, we will use Telnet protocol to verify the vty access to R1 via R2. We set the username as ‘study’ and configure passwords ‘ccnp’ and enable password ‘cisco’ beforehand.

R2#telnet 192.168.1.1Trying 192.168.1.1 ...OpenUser Access VerificationUsername: studyPassword:R1>enPassword:R1#

You can see that the Telnet connectivity went through. Now, if we try to Telnet R1 via R3, it will fail.

R3#telnet 192.168.2.1Trying 192.168.2.1 ...% Connection refused by remote hostR3#

R2 can Telnet to R1 because we have created an ACL to permit R2’s IP address to access R1 via vty. R3 cannot access R1 through its virtual terminal lines because we created and applied an ACL that blocks R3’s IP address.

Download our Free CCNA Study Guide PDF for complete notes on all the CCNA 200-301 exam topics in one book.

We recommend the Cisco CCNA Gold Bootcamp as your main CCNA training course. It’s the highest rated Cisco course online with an average rating of 4.8 from over 30,000 public reviews and is the gold standard in CCNA training:

Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (2)

Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (2024)
Top Articles
How to Calculate FOB price in Import & Export? - EXIMPEDIA
What Is FOB Destination? Everything You Need to Know
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
Non Sequitur
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 6131

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.