ANSWERS: 2
  • There is more than one way but only one way is easy. Option 1: create an ACL and apply it as an inbound access-class on vty 0-4 or vty 0-X as it applies to your version of router/switch and IOS. Option 2: use TACACS+ and setup a login group and limit logins from that group to an address, address range or prefix. In a large router deployment, TACACS+ is a better way to go (but make sure you default to local in case your network is down and cant reach the tacacs+ server)
  • When you say telnet I am assuming you mean ssh. access-list 101 permit 22 {hosts}

Copyright 2023, Wired Ivy, LLC

Answerbag | Terms of Service | Privacy Policy