Using an ACL to Restrict Remote Access to Telnet

Remote access using Telnet, SSH, and SNMP to Ruckus devices can be controlled using standard ACLs.
In this task, Telnet access to a device is restricted by an ACL.
  1. Enter global configuration mode.
    device# configure terminal
  2. Create an access list.
    device(config)# ip access-list extended acl10
  3. Create access-list deny statements.
    device(config-ext-ipacl-acl10)# deny ip host 10.157.22.32 any log
    device(config-ext-ipacl-acl10)# deny ip 10.157.23.0 0.0.0.255 any log
    device(config-ext-ipacl-acl10)# deny ip 10.157.24.0 0.0.0.255 any log
    device(config-ext-ipacl-acl10)# deny ip 10.157.25.0/24 any log
    The example configures deny statements.
  4. Create a permit statement that allows all other IP traffic.
    device(config-ext-ipacl-acl10)# permit ip any any 
    device(config-ext-ipacl-acl10)# exit
    
  5. Apply the access list to restrict Telnet access for any IP address configured in the ACL (acl10 in the example).
    device(config)# telnet access-group acl10
    The device allows Telnet access to all IP addresses except those listed in ACL 10.
  6. Save the configuration by writing it to memory.
    device(config)# write memory

The following example configures an access list to restrict Telnet usage.

device# configure terminal
device(config)# ip access-list extended acl10 
device(config-ext-ipacl-acl10)# deny ip host 10.157.22.32 any log
device(config-ext-ipacl-acl10)# deny ip 10.157.23.0 0.0.0.255 any log
device(config-ext-ipacl-acl10)# deny ip 10.157.24.0 0.0.0.255 any log
device(config-ext-ipacl-acl10)# deny ip 10.157.25.0/24 any log
device(config-ext-ipacl-acl10)# permit ip any any 
device(config-ext-ipacl-acl10)# exit
device(config)# telnet access-group acl10
device(config)# write memory