site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Submit a new forum topic ·Forum FAQ ·Submit a FAQ ·Docs Guidelines and Advisories ·EOS/EOL thread
AuthorAll Replies


state
stress magnet
Premium,Mod
join:2002-02-08
Purgatory
kudos:6

reply to Network Guy

Re: Who keeps their router's SSH port open?

No access lists?

Network Guy
Premium
join:2000-08-25
New York
Reviews:
·Optimum Online

Yes. I only allow local internal subnet and one IP address from my job to access all VTY lines.

The only thing that worries me is that in order to get the ACL to work I had to allow to any that equals 22 and apply it inbound to the VTY lines. I wanted to specify an IP address in the destination but as far as I know, you can't set an IP address to a VTY line.


Network Guy
Premium
join:2000-08-25
New York

1 edit

reply to state
Doh! I checked the VTY lines. I created the ACL but forgot to set it to the lines.

The script kiddie from China is no longer in my NAT statistics table.


Wednesday, 19-Jun 20:46:25 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics