Configuring Remote Access Using Telnet
Telnet support is disabled by default. The following Telnet configuration options are also disabled by default:
- Restriction of Telnet access: Telnet access to the device can be restricted based on the source IP address or MAC address or a combination of IP addresses and MAC addresses.
- Configuration of the number of login attempts before a user is locked out.
- CLI timeout: The number of minutes a Telnet session (or an SSH session) can
remain idle before it is timed out. An idle Telnet session is still sending TCP
ACKs in response to keepalive messages from the device but is not being used to
send data. When the
cli timeoutcommand is configured with a value of 0, no timeout occurs, and the session remains up.
There is no Telnet-specific username and password. AAA authentication is used to secure Telnet access to the device.
Perform the following steps to enable Telnet, configure Telnet session parameters, and restrict Telnet access to a device.
- Enter global configuration mode.
- Enable Telnet. By default, telnet server is disabled and its disabled status is not displayed in the show running-config command.
- Configure the CLI idle
time.The timeout for an inactive CLI session is set to 120 minutes. After 120 minutes of inactivity, the session is disconnected.
- Restrict Telnet access to the device based on the source IP address or MAC address.
Telnet Configuration and Restriction of Telnet Access
The following example enables Telnet and sets the idle timeout and number of login retries. It also permits Telnet access to three specific IP addresses and denies Telnet (and other protocol) access to MAC address CC:4E:24:D0:8B:81.
device# configure terminal device(config)# telnet server device(config)# cli timeout 120 device(config)# management access src-ip 11.10.10.1/32 deny all device(config)# management access mac CC:4E:24:D0:8B:81 deny all device(config)# management access src-ip 10.10.10.0 255.255.255.0 src-ip 1.1.1.1 255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh
Disabling Telnet
The following example shows how to disable Telnet access only to clients connected to ports within port-based VLAN 40.
device# configure terminal device(config)# no telnet server enable vlan 40 device(config)# show running-config | in telnet device(config)#
Terminating or Cancelling a Telnet Outbound Session
If you need to end a Telnet session from the console to a remote Telnet server (for example, if the connection is frozen), you can terminate the Telnet session using one of the following options:
- Press control +
']' at the console. A prompt will appear, and then press the
'e' key to end the Telnet
session.
telnet@ICX7650-48P Router# Console escape. Commands are: l go to line mode c go to character mode z suspend telnet e exit telnet
-
Type 'quit' at the console and press enter. You will enter user execution mode, then type 'quit' again and press enter at the console. Your outbound Telnet connection is now closed.
ICX7650-48P Router# telnet 10.176.160.78 Entering character mode Escape character is '^]'. Ruckus-ICX_RODAN login: test Password: telnet@km1128(config-vlan-22)# quit telnet@km1128> quit Connection closed by foreign host ICX7650-48P Router#