Configure local authentication for Telnet with username ADMIN password cisco

hostname r1

aaa new-model aaa authentication login vty local-case !

username ADMIN password 7 00071A150754 !

access-list 110 permit tcp any any eq telnet time-range work-hours !

line vty 0 4 access-class 110 in login authentication vty

time-range work-hours periodic weekdays 9:00 to 17:00

Verify Telnet from R2 to R1. r1#clock set 14:40:00 May 21 2003 r1#show clock

14:40:12.319 AST Wed May 21 2003

r1#who

Line User

6 6 vty 0 ADMIN

Interface User

Host(s)

idle idle

Mode

Idle Location

00:00:00

00:00:09 172.16.1.10 Idle Peer Address r1#show time-range time-range entry: work-hours (active) periodic weekdays 9:00 to 17:00 used in: IP ACL entry r1#show access-lists 110 Extended IP access list 110

permit tcp any any eq telnet time-range work-hours (active) (2 matches)

! Change the clock to something not between 9:00am to 5:00pm r1#clock set 2:40:00 May 21 2003 r1#show clock

02:40:02.987 AST Wed May 21 2003 r1#who

Line User Host(s) Idle Location

Interface User Mode Idle Peer Address r1#show time-range time-range entry: work-hours (inactive) periodic weekdays 9:00 to 17:00

used in: IP ACL entry r1#show access-lists 110 Extended IP access list 110

permit tcp any any eq telnet time-range work-hours (inactive) (2 matches)

Hidden issue: Configure case-sensitive local authentication, as user ADMIN is in uppercase and password is in lowercase. This provides added security.

Configure PIX with static NAT and ACL to achieve this task:

pixfirewall(config)# show static static (inside,outside) 175.1.2.20 172.16.1.2 netmask 255.255.255.255 0 0

pixfirewall(config)# show access-list access-list 101 permit tcp any host 175.1.2.20 eq telnet (hitcnt=7)

Was this article helpful?

0 0