dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
2
share rss forum feed


state
stress magnet
Premium,Mod
join:2002-02-08
Purgatory
kudos:6
reply to Network Guy

Re: Who keeps their router's SSH port open?

No access lists?

Network Guy
Premium
join:2000-08-25
New York
kudos:2
Reviews:
·Future Nine Corp..
·T-Mobile US
Yes. I only allow local internal subnet and one IP address from my job to access all VTY lines.

The only thing that worries me is that in order to get the ACL to work I had to allow to any that equals 22 and apply it inbound to the VTY lines. I wanted to specify an IP address in the destination but as far as I know, you can't set an IP address to a VTY line.

Network Guy
Premium
join:2000-08-25
New York
kudos:2

1 edit
reply to state
Doh! I checked the VTY lines. I created the ACL but forgot to set it to the lines.

The script kiddie from China is no longer in my NAT statistics table.