Professional Documents
Culture Documents
08 - How To Deny Telnet or SSH Services
08 - How To Deny Telnet or SSH Services
That means whichever rule comes first takes precedence. If the first part of the ACL denies traffic, but a lower part of the
ACL allows it, the router will still deny the traffic. Let's look at an example:
Nexus Education Services Address: Suite 1611 16th Floor AIC Burgundy Empire Tower ADB Ave corner Garnet Road Ortigas Center Pasig
☎ Globe: 0995-573-8873 ☎ Smart:0999-816-5357 ☎ PLDT: 584-1881 / 788-1420 / 788-1419 website: www.nexusph.net
Page |2
! R1
conf t
hostname R1
no ip domain-lookup
int e0/0
ip address 11.0.0.1 255.0.0.0
no shut
int FastEthernet1/0
speed 100
duplex full
ip address 10.0.0.1 255.0.0.0
no shut
! create a route
router eigrp 10
network 10.0.0.0
network 11.0.0.0
network 12.0.0.0
Nexus Education Services Address: Suite 1611 16th Floor AIC Burgundy Empire Tower ADB Ave corner Garnet Road Ortigas Center Pasig
☎ Globe: 0995-573-8873 ☎ Smart:0999-816-5357 ☎ PLDT: 584-1881 / 788-1420 / 788-1419 website: www.nexusph.net
Page |3
end
wr
! R2
conf t
hostname R2
int e0/0
duplex full
speed 100
ip address 11.0.0.2 255.0.0.0
no shut
int FastEthernet1/0
duplex full
speed 100
ip address 12.0.0.1 255.0.0.0
no shut
! create a route
router eigrp 10
network 10.0.0.0
network 12.0.0.0
end
wr
! R3
conf t
hostname R3
no ip domain-lookup
int FastEthernet1/0
duplex full
speed 100
ip address 10.0.0.2 255.0.0.0
no shut
router eigrp 10
network 11.0.0.0
network 12.0.0.0
end
! R4
conf t
hostname R4
no ip domain-lookup
int FastEthernet1/0
duplex full
speed 100
ip address 12.0.0.2 255.0.0.0
no shut
router eigrp 10
network 10.0.0.0
network 11.0.0.0
end
Nexus Education Services Address: Suite 1611 16th Floor AIC Burgundy Empire Tower ADB Ave corner Garnet Road Ortigas Center Pasig
☎ Globe: 0995-573-8873 ☎ Smart:0999-816-5357 ☎ PLDT: 584-1881 / 788-1420 / 788-1419 website: www.nexusph.net
Page |5
R3#telnet 12.0.0.2
Trying 12.0.0.2 ... Open
User Access Verification
Username: cisco
Password: {type cisco}
R4>en
Password: {secret}
R4#
! type exit to return to R3
R4#exit
[Connection to 12.0.0.2 closed by foreign host]
R3#
conf t
! config name based ACL
ip access-list extended nexus_ACL
deny tcp host 10.0.0.2 host 12.0.0.2 eq telnet
deny tcp host 10.0.0.2 host 12.0.0.2 eq 22
int FastEthernet1/0
ip access-group nexus_ACL in
Nexus Education Services Address: Suite 1611 16th Floor AIC Burgundy Empire Tower ADB Ave corner Garnet Road Ortigas Center Pasig
☎ Globe: 0995-573-8873 ☎ Smart:0999-816-5357 ☎ PLDT: 584-1881 / 788-1420 / 788-1419 website: www.nexusph.net
Page |6
R3#telnet 12.0.0.2
Trying 12.0.0.2 ...
% Destination unreachable; gateway or host down
Nexus Education Services Address: Suite 1611 16th Floor AIC Burgundy Empire Tower ADB Ave corner Garnet Road Ortigas Center Pasig
☎ Globe: 0995-573-8873 ☎ Smart:0999-816-5357 ☎ PLDT: 584-1881 / 788-1420 / 788-1419 website: www.nexusph.net