ssh access-group

Configures an ACL that restricts SSH access to the device.
Syntax
ssh access-group { acl-num | acl-name | ipv6 ipv6-acl-name }
no ssh access-group { acl-num | acl-name | ipv6 ipv6-acl-name }
Command Default

SSH access is not restricted.

Parameters
acl-num
The standard access list number. The valid values are from 1 through 99.
acl-name
The standard access list name.
ipv6 ipv6-acl-name
The IPv6 access list name.
Modes

Global configuration mode

Usage Guidelines

The no form of the command removes the SSH access restriction.

Examples

The following example shows how to configure an ACL that restricts SSH access to the device. In this example, ACL 12 is configured. The device allows SSH access to all IP addresses except those listed in ACL 12.

device(config)# ip access-list standard 12 
device(config-std-ipacl-12)# deny host 10.157.22.98 log
device(config-std-ipacl-12)# deny 10.157.23.0 0.0.0.255 log
device(config-std-ipacl-12)# deny 10.157.24.0/24 log
device(config-std-ipacl-12)# permit any
device(config-std-ipacl-12)# exit
device(config)# ssh access-group 12
device(config)# write memory