SSH and Telnet access for catalyst 4503 list

I was wondering the structure of command to apply an access list to ssh and telnet on a catalyst 4503. I keep a list of access for indoors and outdoors. Can afford two different IPs from the outside? Thank you

You will need create an access list indicating the networks/hosts that you want to allow.

-Example

access-list 10 permit 10.10.1.10

access-list 10 permit 10.10.2.10

access-list 10 permit 127.1.0.0 0.0.255.255

access-list 10 permit 192.168.1.0 0.0.0.255

So you want to put this list of access on the VTY interfaces.

-Example

line vty 0 4

access-class 10

entry ssh transport * if you only want to SSH *.

line vty 5 15

access-class 10

entry ssh transport * Ditto *.

Now you can do all this with * line vty 0 15 * but, it gives you a better idea of what is happening. It is a simplistic configuration. Remember that it is advisable not to allow ssh. If you want to allow at the same time, let him * transport input ssh * out of the configuration.

I hope that gives you an idea of the structure. If this is not the case, let me know.

Tags: Cisco Security

Similar Questions

  • I disabled the menu and cannot access the drop-down list to get back them

    I disabled all the menus to make a screenshot and now I can't access the drop-down list to get back them

    This has happened

    Just once or twice

    is today

    You can hide the menu bar in Firefox 3.6 on Windows, on "view > toolbars" or via the contextual right click menu on a toolbar.
    Press in and hold the Alt key to display the menu bar.
    Go to "view > toolbars", right click on the menu bar, or press Alt + V T to select the toolbars to show or hide.

    See also what happened to the file, edit and view menus?

  • C4580 install disables the XP firewall and internet access for 3 minutes at the start of the PC

    After installing C4580, when I turn on my Dell Inspiron C510m, XP tells me that the firewall is disabled, I can't access to the internet or even my router nor can I use the Applets in Control Panel that could help me sort these things. After 3 minutes, the Firewall WARNING disappears and everything is fine, but none of the updates antivirus and software update checks performed and I have to perform these tasks manually. The printer works fine, but it worries me that this behavior indicates a potential vulnerability - it's like something kept the door open to let the unpleasant things in the computer. Uninstall the HP software solves the problem, and he re - install it reminds me once again. There is something hanging in a HP driver at startup?

    PeterM

    I found the answer to this one, if anyone is interested, even if the solution required a work-around on the way. Suggested HP support I have just uninstall and install software downloaded from their site (PS_AIO_04_C4500_USW_Full_Win_enu_120_210.exe). This indeed solve, and another problem I had (see network & Wireless forum), but this download is missing the software package I.R.I.S. OCR, presumably for reasons associated with 3 rd-party lisensing. HP support insisted that this download was the OCR, but the OCR .exe is certainly missing. Workaround needed to go back and re - install the CD software, then uninstall everything except the OCR package (you can do), then install the downloaded version. My PC still takes too long to start, but it's probably the combined effect of each software package, I never installed wanting home phone so that it loads.

    PeterM

  • Native SSH and SFTP in LabVIEW

    At the risk of re-opening a Pandora's box, there is no consideration to add native SSH and SFTP support for LabVIEW?

    Using PuTTY/plink is heavy and not multiplatform.

    Calling a .NET (or other) an external assembly is heavy and not multiplatform.

    Labwerx SSH has a license model terrible (not to mention the extra cost).

    It is the year 2015, and SSH/SFTP is ubiquitous and does not go far. These protocols must be present natively in LabVIEW.

    I saw this idea on the Exchange (http://forums.ni.com/t5/LabVIEW-Idea-Exchange/Native-SSH-and-SFTP-Support/idi-p/1141529), , but there is no movement in 5 years. I'd like to get news of NEITHER here, even in the negative. If LabVIEW does not take over SSH any time soon, it would be better to know now.

    I doubt that this is likely to happen any time soon - the LabSSH Toolbox is a fairly reasonable price when compared to how long it would take to implement the feature yourself and there is nothing for you prevent its implementation yourself using the TCP/IP functions located in LabVIEW. Of course, you can use the command line to something like WinSCP / PuTTy as well.

    I also found a wrapper that someone had done for an Open Source .NET SSH library called in-depth

    I downloaded a copy of this thread: http://forums.ni.com/t5/LabVIEW/Plink-PuTTY-works-30-of-the-time-using-System-Exec-vi/td-p/3002261

    There is also an alternative implementation of wrapper here: https://decibel.ni.com/content/docs/DOC-41388

  • Enable SSH and disable Telnet

    I try to activate SSH on a 3560G switch so I can't disable Telnet.

    Some referred to a "sh-ssh' to see if I have ssh on the switch. It does not show. I also have 'transport input ssh' and ssh is not a valid input method.

    I've decided to update the IOS on the switch. I am now at 12.2 (52) SE.

    But I can not configure SSH. I get the same results as mentioned above.

    Since it is the latest version of IOS can't I not assume that it contains SSH? Or do I need to download another version of IOS who specifically has SSH in?

    Thanks for your help

    There are two versions of the images switch Catalyst (K9/SSH and SSH). If you do a ' show versi
    on "it displays the latest version of IOS running on the switch. If you run a non - ssh version, you must upgrade to a ssh (K9) image.

    Concerning

    Farrukh

  • Separation of monitor only and Admin for Cisco ASDM (ASA) access for users authenticated via LDAP

    Hello

    We have two groups of ads on network Admins, one for the system administrators group. The network Admins will get Priv lvl 15 the other Priv lvl 3.

    This is the setup I use:

    TestASA # sh run ldap-attribute-map of test4
    Comment by card privileged-level name
    map-value comment fw - ro 5
    map-value comment fw - rw 15
    memberOf IETF Radius-Service-Type card name
    map-value memberOf "cn = s-FW-Admin, OR = security groups, DC = 802101, DC = local" 6
    map-value memberOf "cn = s-fw-ro, OR = security groups, DC = 802101, DC = local" 5

    The user in both groups can connect ssh and asdm but all users get the same rights priv lvl 15.

    Someone at - it an idea?

    You must visit the listed link below to configure ASA to only read access and access admin. not sure, if you have already been there.

    https://supportforums.Cisco.com/docs/doc-33843

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • I have three problems___the is first I get the error messages form I mesh and cannot access my profile or friends list ' ___Microsoft online which is a whoosie of my gave me element to modify registry keys but no items exist in the regisry

    I get the error messages form I mesh and cannot access my profile or friends list '

    MIicrosoft online which is a whoosie of my gave me element to modify registry keys but no items exist in the regisry

    For iMesh, you can go here...

    http://www.iMesh.com/community.html

    I don't understand the other two problems that you encounter.  If you please would explain what they are and what, if any, error messages that you receive.  Also, what antivirus do you use, and you run Windows XP SP3?

    --
    Gina Whipp
    Microsoft MVP (access)

    Please post all responses on the forum where everyone can enjoy.

  • Critical auth and limited access-list

    I play just with ISE 1.1.4 and auth critical, but I have a pretty locked down from the default access on ports list. Is it possible to replace a list of very restrictive access by default in the event of critical auth?

    It seems as if you are relieant on DACLs to provide access for devices (closed or similar mode) auth criticism is not a viable option?

    Or have I misunderstood, and perhaps "action dead event server authentication allows voice" more I waited.

    I guess I'm looking for something like "event action dead access-list less-restrictiveACL server authentication."

    Thank you

    Gas

    Why not flip it on its head and have your less-restrictive-ACL default and impose more restrictive things through dACL?

  • Access for interal AND external users through a single login server?

    Hey,.

    Apart from redundancy, it is possible to have a single connection server that allows internal users AND external access virtual resources?

    For external access, I have associated my login server security server. It works perfectly if I activate the PCoIP Secure Gateway option on my server of connection and enter the public IP address of the Security server.

    But with this configuration internal users are not able to connect (listing the works of resources, but the connection fails).

    If I disable the PCoIP Secure Gateway option, internal users can access, but not external users via the Security server.

    Any contribution is appreciated.

    Thank you very much!

    No, it's the only way you can do it for internal users and external to share the same login server - activation of the MTP setting is by CS. If you want to PSG on for external users (and it is practically a necessity unless you use a third-party VPN), but offshore for internal users, they will point to the servers of different connection and so you'll need two.

  • Is it possible to access the USB ports and a slot for card SDX?

    Is it possible to access the USB ports and a slot for SDX card at the back of the iMac?

    Rotate the iMac autour to see ports.

  • Account has been locked and cannot access messages or retrieve my addresses. Have not received my new password for Microsoft.

    Have been locked out of my account for seven days

    and cannot access messages or retrieve my addresses.  Cause a lot of stress.  No guard MS saying that they will send me a new password BUYMD.  I've set up account about 14 years and I don't remember my safe Word now.  How can I switch back to my account?  MS wrote they will send my password to the account of spare * address email is removed from the privacy *, but DO NOT.  Is the account I'm stuck on * address email is removed from the privacy * HELP!  Kirsten Ebsen

    Hello

    To expand a bit on the right information to Debbie C.:

    Answers is a peer group supported and unfortunately has no real influence on Hotmail.

    HotMail has its own Forums, so you can ask your questions there.

    Windows Live Solution Center - HotMail - HotMail Forums Solutions
    http://windowslivehelp.com/

    Hotmail - Forums
    http://windowslivehelp.com/forums.aspx?ProductID=1

    Hotmail - Solutions
    http://windowslivehelp.com/solutions.aspx?ProductID=1

    How to contact Windows Live Hotmail Support
    http://email.about.com/od/hotmailtips/Qt/et_hotmail_supp.htm

    Windows Live Hotmail Top issues and Support information
    http://support.Microsoft.com/kb/316659/en-us

    Error message "your account has been locked" when trying to connect
    http://windowslivehelp.com/thread.aspx?ThreadId=77be7d82-a0e9-49c7-b46d-040ec654a9e2

    Compromised account - access unauthorized account - how to recover your account
    http://windowslivehelp.com/solution.aspx?SolutionID=6ea0c7b3-1473-4176-b03f-145b951dcb41

    Hotmail hacked? Take these steps
    http://blogs.msdn.com/b/securitytipstalk/archive/2010/07/07/Hotmail-hacked-take-these-steps.aspx

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle="" -="" mark="" twain="" said="" it="">

  • How to use Ssh and Https for PC8164 PC5524

    Hello!

    How to use SSH and Https to connect to PC8164 and PC5524?

    Kind regards!

    For SSH configuration, we want to watch the 1651 page controls, user guide.

    (config) #crypto console key generate rsa

    RSA key generation started, it may take a few minutes...

    Complete RSA key generation.

    #crypto console key (config) generate dsa

    DSA key generation started, it may take a few minutes...

    DSA key generation complete.

    Console (config) #ip ssh server

    For HTTPS orders, we look at page 255, 1770-1778, CLI Guide.

    generate a crypto certificate of console (config) # 1

    Console (config-crypto-cert) #key - generate

    output console(config-crypto-CERT) #.

    Console (config) # ip http secure-certificate 1

    Console (config) # ip http secure server

  • CUPS, Jabber IM for iPhone, Mobile and external access

    Hello world

    How do you provide external secure access for email Instant Jabber for iPhone client and the Cisco Mobile customer on an iPhone?

    There are so-called security SSL for Jabber Instant Messaging, but is unable to find all the information on how. The Cisco Mobile client appears to the needs of the AnyConnect VPN client and encourage users to connect via VPN, first...

    After a bit of bumping into a wall your head wondering why there was no documentation for external access to Cisco Jabber for iPhone, I realized that Cisco Jabber IM for iPhone is an entirely different product and Jabber for iPhone seems to be the new name of Cisco Mobile customers. Yet, the only documentation I can find for the Jabber Instant Messaging is that I can "security by using the Secure Sockets Layer (SSL) encryption" but no information on implimenting it with CUPS.

    On top of that, the Jabber IM for iPhone can not make calls but rather calls Cisco Mobile, which raises the question of providing external access to this too, and the only solution I've ever found is to use the AnyConnect VPN client on the device also. Suddenly, it seems to offer a solution of Cisco Unified Communications on an iPhone, I need three different and is applications is no longer quite as unified.

    Thank you

    Mark

    Conclusions you drew on the product names are correct. They are transitioning to Jabber like a brand name, but it did not in the iOS VoIP client yet. The most recent Cisco Jabber for Android is the first to include Secure Connect (remote access protected or ensure access transparent, aka). The BU seems characteristic knocking out on a single platform and then replicating them on others before moving on to the next batch of features. I don't have a specific timetable to share but expect customers to iOS updated in the coming months with Secure Connect.

    With regard to the separate clients: I can see both sides of this room. The more I use them more, I agree with the decision to keep them separated and cross-launch when necessary. If you think it is consistent with the way the user interacts already with their phone: voice and texting are two separate applications. I suspect that the developers also get some benefits by keeping things more targeted (e.g. less than test whenever they change something). The only downside to this approach is that each app consumes its own tunnel AnyConnect on the SAA.

  • Eight versions of Visual C++ (x 64 and x 86 for 2010) listed

    Eight versions of Visual C++ listed in the software uninstall list, but none listed in Windows Explorer.  Can I uninstall and reinstall the last two (x 64 and x 86 for 2010)?  I have not deliberately installed one of these versions.  Do I need all of them?  How to open one of them to create the Visual C++ source code?

    Eight versions of Visual C++ listed in the software uninstall list, but none listed in Windows Explorer.  Can I uninstall and reinstall the last two (x 64 and x 86 for 2010)?  I have not deliberately installed one of these versions.  Do I need all of them?  How to open one of them to create the Visual C++ source code?

    The eight versions of C + seems to have been installed on my computer while I was uninstalling software downloaded by a pirate.

    I'm just an average user and do not do programming.  Am I correct in that these programs are probably more spyware?  I read somewhere to never uninstall them.  Is that a programmer or we normal people who have been hacked?

    Thanks in advance for the pearls of wisdom you can share :)

  • I am on a trial with Acrobat Pro DC on a Mac and when I try to combine files for example a pdf file and a word doc it says "additional permissions to access to" the word doc, so I have to select a folder and grant access, etc.  It's too long - is the

    I am on a trial with Acrobat Pro DC on a Mac and when I try to combine files for example a pdf file and a word doc it says "additional permissions to access to" the word doc, so I have to select a folder and grant access, etc.  It's too long - is there a way to get around this?

    Hi Alex,

    This is not related to Acrobat, Microsoft, you can see this problem with Microsoft Word is known: grant access file: cannot open the document: user - Microsoft Community it is a sandbox application. It restricts user with several workflow.

    Unfortunately, there isn't much we can help at this stage.

    Kind regards

    Tariq Dar.

Maybe you are looking for

  • How can I change where firefox stores the logs?

    I run 'Fox on a flash drive, because it allows me to keep my history, bookmarks, etc. all together while using ' Fox on several different computers. I learned recently that Firefox was leaving newspapers on the hard drives of each computer, that I ra

  • G3 Netbook 240: loading Windows 7 on HP x 64 G3

    I have Netbook a friend where he wanted me to remove Windows 8 and it back to Windows 7. I installed Windows 7 from a USB Pendrive with no problems, BUT now that it is installed the internet or USB ports of work due to a lack of drivers. I downloaded

  • Broken screen - data recovery is not possible?

    Hi all I have a RAZR Maxx HD with a digitizer of cracking, the screen is not visible at all. Is it possible to connect it to my laptop to extract data before that I have to send it back (since I already have the insurance replacement)? I know there a

  • IdeaPad U510 - change boot order

    Hello! I received a U510 for Christmas and I want to perform a new installation of Windows 8 via the USB port. Every time I restart the machine, the LENOVO screen, I press F12 but any bootmenu will appear. There's no option by entering the BIOS eithe

  • Disk space room of Windows Vista (c) (why it is nearly full?)

    I have Vista and my question is on my C drive. My local disk fills up really quick. I deleted almost all the files and I don't have a lot of programs.  The program, which takes the most space is iTunes. What could I do to know what takes up all my sp