"Is there any compelling reason why SSH should only be allowed to one particular IP on the router?"
Yes, if you have VRF's setup and only want to allow inbound traffic to particular interfaces in a particular VRF (or default/global)... Fred Reimer, CISSP Senior Network Engineer Coleman Technologies, Inc. 954-298-1697 -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of C and C Dominte Sent: Friday, September 14, 2007 2:54 AM To: Tom Storey; [email protected] Subject: Re: [c-nsp] vty access-list Try permitting based on IP address only, e.g. access-list 199 permit ip x.x.x.x 0.0.0.255 host y.y.y.y still the same result, all the ip's are blocked. Well you are allowing TCP port 22 from x.x.x.x/24 to any destination, which will be any IP address on the router. But that doesnt neccessarily explain why the first access list doesnt work. Personally Ive never used an extended ACL to control VTY access to a router, I generally use standard ACLs and permit only a specific set of source subnets access. It works just fine. I wanted to use that, but I thought it is easier to cut the access to a destination, rather than cut the access based on source address. This way, I don't have to RDP / SSH to my desktops, to be able to connect to the router. Is there any compelling reason why SSH should only be allowed to one particular IP on the router? I wanted to see if I can force the router to allow SSH traffic only on one IP interface, not on all of them. Thanks, Catalin --------------------------------- Yahoo! Answers - Get better answers from someone who knows. Tryit now. _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
