Configure local authentication for Telnet with username ADMIN password cisco
hostname r1
aaa new-model aaa authentication login vty local-case !
username ADMIN password 7 00071A150754 !
access-list 110 permit tcp any any eq telnet time-range work-hours !
line vty 0 4 access-class 110 in login authentication vty
time-range work-hours periodic weekdays 9:00 to 17:00
Verify Telnet from R2 to R1. r1#clock set 14:40:00 May 21 2003 r1#show clock
14:40:12.319 AST Wed May 21 2003
r1#who
Line User
6 6 vty 0 ADMIN
Interface User
Host(s)
idle idle
Mode
Idle Location
00:00:00
00:00:09 172.16.1.10 Idle Peer Address r1#show time-range time-range entry: work-hours (active) periodic weekdays 9:00 to 17:00 used in: IP ACL entry r1#show access-lists 110 Extended IP access list 110
permit tcp any any eq telnet time-range work-hours (active) (2 matches)
! Change the clock to something not between 9:00am to 5:00pm r1#clock set 2:40:00 May 21 2003 r1#show clock
02:40:02.987 AST Wed May 21 2003 r1#who
Line User Host(s) Idle Location
Interface User Mode Idle Peer Address r1#show time-range time-range entry: work-hours (inactive) periodic weekdays 9:00 to 17:00
used in: IP ACL entry r1#show access-lists 110 Extended IP access list 110
permit tcp any any eq telnet time-range work-hours (inactive) (2 matches)
Hidden issue: Configure case-sensitive local authentication, as user ADMIN is in uppercase and password is in lowercase. This provides added security.
Configure PIX with static NAT and ACL to achieve this task:
pixfirewall(config)# show static static (inside,outside) 175.1.2.20 172.16.1.2 netmask 255.255.255.255 0 0
pixfirewall(config)# show access-list access-list 101 permit tcp any host 175.1.2.20 eq telnet (hitcnt=7)
Was this article helpful?