Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (2024)

Remote access via virtual terminal or virtual tty (vty) lines can also be secured by configuring inbound and outbound Access Control Lists (ACLs). Inbound ACLs enable inbound connections to a Cisco device, router or switch, from a restricted list of IP addresses. On the other hand, outbound ACLs controls outbound access from Cisco devices. The best practice is to allow internal or trusted network IP addresses to access the vty lines.

ACL Configuration on VTY Lines

To configure standard or extended ACL on a vty line, we use the ‘access-class {access-list-number|access-list-name} {in|out}‘ configuration commands. We enter the command under the vty line configuration mode.

For our example, we have routers R1, R2, and R3 here. We want R1 to allow connections with R2 but not with R3.Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (1)

First, we have to create our access lists on R1’s global configuration mode. We will have two standard access lists, one to permit R2 at 192.168.1.10 and one to block R3 with an IP address of 192.168.2.10 for this example. We will use the access list number 1. Enter the following commands:

R1(config)#access-list 1 permit 192.168.1.10R1(config)#access-list 1 deny 192.168.2.10

Then, we will apply the ACL we’ve created to the vty lines to permit Telnet or SSH traffic. We will use the ‘access-class’ command under the vty line configuration mode. We have to specify the access list number, which is 1, and we will use the keyword ‘in’ for inbound ACL. This is to control inbound Telnet connections. Enter configuration commands one per line:

R1(config)#line vty 0 4R1(config-line)#access-class 1 inR1(config-line)# exit

Verifying ACL Access on VTY Lines

To view the configurations under the vty lines, we can use the ‘show running-config | section line vty’ command.

R1# show running-config | section line vtyline vty 0 4access-class 1 inlogin local

To check our vty connectivity, we can use Telnet or SSH (Secure Shell). In our example, we will use Telnet protocol to verify the vty access to R1 via R2. We set the username as ‘study’ and configure passwords ‘ccnp’ and enable password ‘cisco’ beforehand.

R2#telnet 192.168.1.1Trying 192.168.1.1 ...OpenUser Access VerificationUsername: studyPassword:R1>enPassword:R1#

You can see that the Telnet connectivity went through. Now, if we try to Telnet R1 via R3, it will fail.

R3#telnet 192.168.2.1Trying 192.168.2.1 ...% Connection refused by remote hostR3#

R2 can Telnet to R1 because we have created an ACL to permit R2’s IP address to access R1 via vty. R3 cannot access R1 through its virtual terminal lines because we created and applied an ACL that blocks R3’s IP address.

Download our Free CCNA Study Guide PDF for complete notes on all the CCNA 200-301 exam topics in one book.

We recommend the Cisco CCNA Gold Bootcamp as your main CCNA training course. It’s the highest rated Cisco course online with an average rating of 4.8 from over 30,000 public reviews and is the gold standard in CCNA training:

Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (2)

Virtual Terminal (VTY) Lines with Access Control List - Study CCNP (2024)
Top Articles
FINRA Approves WisdomTree to Transact in Blockchain-Enabled Funds
Reader’s Question: What To Invest In After The Company Match
Antisis City/Antisis City Gym
Skylar Vox Bra Size
How Much Does Dr Pol Charge To Deliver A Calf
Comcast Xfinity Outage in Kipton, Ohio
About Goodwill – Goodwill NY/NJ
Craigslist Labor Gigs Albuquerque
Red Heeler Dog Breed Info, Pictures, Facts, Puppy Price & FAQs
Theycallmemissblue
Kinkos Whittier
Flights To Frankfort Kentucky
Viha Email Login
NHS England » Winter and H2 priorities
Indiana Wesleyan Transcripts
Icivics The Electoral Process Answer Key
Heart and Vascular Clinic in Monticello - North Memorial Health
Morristown Daily Record Obituary
Trivago Myrtle Beach Hotels
eugene bicycles - craigslist
Hctc Speed Test
Discord Nuker Bot Invite
Urban Dictionary Fov
Nearest Ups Ground Drop Off
2004 Honda Odyssey Firing Order
LG UN90 65" 4K Smart UHD TV - 65UN9000AUJ | LG CA
Otis Inmate Locator
Used Safari Condo Alto R1723 For Sale
Prévisions météo Paris à 15 jours - 1er site météo pour l'île-de-France
Helloid Worthington Login
Play 1v1 LOL 66 EZ → UNBLOCKED on 66games.io
Tamil Play.com
Marine Forecast Sandy Hook To Manasquan Inlet
Edict Of Force Poe
دانلود سریال خاندان اژدها دیجی موویز
Myql Loan Login
Mvnt Merchant Services
Stanley Steemer Johnson City Tn
Xxn Abbreviation List 2023
Best GoMovies Alternatives
Tgirls Philly
فیلم گارد ساحلی زیرنویس فارسی بدون سانسور تاینی موویز
Gabrielle Abbate Obituary
15 Best Places to Visit in the Northeast During Summer
Swsnj Warehousing Inc
Pas Bcbs Prefix
Enter The Gungeon Gunther
El Patron Menu Bardstown Ky
Pronósticos Gulfstream Park Nicoletti
The 5 Types of Intimacy Every Healthy Relationship Needs | All Points North
Where Is Darla-Jean Stanton Now
Divisadero Florist
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 6131

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.