Configuring Remote Access Using Telnet

Telnet can be used to remotely access the CLI of an ICX switch. You can configure connection parameters such as idle timeouts and Telnet access restrictions based on IP and MAC addresses to secure access to the device.

Telnet support is disabled by default. The following Telnet configuration options are also disabled by default:

  • Restriction of Telnet access: Telnet access to the device can be restricted based on the source IP address or MAC address or a combination of IP addresses and MAC addresses.
  • Configuration of the number of login attempts before a user is locked out.
  • CLI timeout: The number of minutes a Telnet session (or an SSH session) can remain idle before it is timed out. An idle Telnet session is still sending TCP ACKs in response to keepalive messages from the device but is not being used to send data. When the cli timeout command is configured with a value of 0, no timeout occurs, and the session remains up.
Note: RUCKUS ICX 8100 devices support five inbound Telnet sessions and five outbound Telnet sessions.

There is no Telnet-specific username and password. AAA authentication is used to secure Telnet access to the device.

Perform the following steps to enable Telnet, configure Telnet session parameters, and restrict Telnet access to a device.

  1. Enter global configuration mode.
    device# configure terminal
  2. Enable Telnet. By default, telnet server is disabled and its disabled status is not displayed in the show running-config command.
    device(config)# telnet server enable VLAN 1
    device(config)# show running-config | in telnet
    telnet server enable vlan 1
    
  3. Configure the CLI idle time.
    device(config)# cli timeout 120
    The timeout for an inactive CLI session is set to 120 minutes. After 120 minutes of inactivity, the session is disconnected.
  4. Restrict Telnet access to the device based on the source IP address or MAC address.
    device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow telnet 
    device(config)# management access mac 00:00:00:0f:e9:a0 allow telnet 

Telnet Configuration and Restriction of Telnet Access

The following example enables Telnet and sets the idle timeout and number of login retries. It also permits Telnet access to three specific IP addresses and denies Telnet (and other protocol) access to MAC address CC:4E:24:D0:8B:81.

device# configure terminal
device(config)# telnet server
device(config)# cli timeout 120
device(config)# management access src-ip 11.10.10.1/32 deny all
device(config)# management access mac CC:4E:24:D0:8B:81 deny all
device(config)# management access src-ip 10.10.10.0 255.255.255.0 src-ip 1.1.1.1 255.255.255.255 mac CC:4E:24:D0:8B:81 allow telnet ssh 

Disabling Telnet

The following example shows how to disable Telnet access only to clients connected to ports within port-based VLAN 40.

device# configure terminal
device(config)# no telnet server enable vlan 40
device(config)# show running-config | in telnet
device(config)#

Terminating or Cancelling a Telnet Outbound Session

If you need to end a Telnet session from the console to a remote Telnet server (for example, if the connection is frozen), you can terminate the Telnet session using one of the following options:

  • Press control + ']' at the console. A prompt will appear, and then press the 'e' key to end the Telnet session.
    telnet@ICX7650-48P Router#
    Console escape. Commands are:
    
     l go to line mode
     c go to character mode
     z suspend telnet
     e exit telnet

  • Type 'quit' at the console and press enter. You will enter user execution mode, then type 'quit' again and press enter at the console. Your outbound Telnet connection is now closed.

    ICX7650-48P Router# telnet 10.176.160.78
    
    Entering character mode
    Escape character is '^]'.
    
    Ruckus-ICX_RODAN login: test
    Password:
    
    telnet@km1128(config-vlan-22)# quit
    telnet@km1128> quit
    Connection closed by foreign host
    ICX7650-48P Router#

Displaying the Telnet Connections and Status

The following show telnet command output displays the Telnet connections and status.

device# show telnet
Telnet server status: Enabled
Telnet connections:
device#