Using an ACL to Restrict Remote Access to Telnet
Remote access using Telnet, SSH, and SNMP to Ruckus devices can be controlled using
standard ACLs.
- Enter global configuration mode.
- Create an access list.
- Create access-list deny
statements.
device(config-ext-ipacl-acl10)# deny ip host 10.157.22.32 any log device(config-ext-ipacl-acl10)# deny ip 10.157.23.0 0.0.0.255 any log device(config-ext-ipacl-acl10)# deny ip 10.157.24.0 0.0.0.255 any log device(config-ext-ipacl-acl10)# deny ip 10.157.25.0/24 any log
The example configures deny statements. - Create a permit statement that allows all other IP traffic.
- Apply the access list to
restrict Telnet access for any IP address configured in the ACL (acl10 in the
example). The device allows Telnet access to all IP addresses except those listed in ACL 10.
- Save the configuration by writing it to memory.
The following example configures an access list to restrict Telnet usage.
device# configure terminal device(config)# ip access-list extended acl10 device(config-ext-ipacl-acl10)# deny ip host 10.157.22.32 any log device(config-ext-ipacl-acl10)# deny ip 10.157.23.0 0.0.0.255 any log device(config-ext-ipacl-acl10)# deny ip 10.157.24.0 0.0.0.255 any log device(config-ext-ipacl-acl10)# deny ip 10.157.25.0/24 any log device(config-ext-ipacl-acl10)# permit ip any any device(config-ext-ipacl-acl10)# exit device(config)# telnet access-group acl10 device(config)# write memory