Line Access

On a standard Cisco router, there are three primary ways to log on:

• Vty line (line vty 0 4, though some routers go to 15)

Fresh out of the box, only the console and aux ports can be used to access the device. Generally, only t console port is needed and not the aux port. To set up the console port, enter the following commands:

Router(config)#line con 0 Router(config-line)#exec-timeout 5 0 Router(config-line)#password password Router(config-line)#login

These commands enable login with a local password and time out the connection after 5 minutes and 0 of inactivity.

To disable the aux port, type the following commands:

Router(config)#line aux 0 Router(config-line)#no exec

Turning off exec prevents logon to the device. Any additional commands such as transport input non exec-timeout 0 1 aren't going to make you more secure, but feel free to type them if you want. Contr access is separate and requires the following commands:

Router(config)#line vty 0 3 Router(config-line)#exec-timeout 5 0 Router(config-line)#password password Router(config-line)#login

Router(config-line)#transport input protocol

Typically, a router has 5 vty lines. The preceding four commands set up access in a very similar fashion console port. Replace protocol with your method of access, preferably SSH.

The following eight lines reserve the last vty port for a specific IP address. This is useful if someone is at to deny service to the login process on the router (which can be done without the password). You can u access class settings referenced here for lines 0 to 3 as well. If you do, open the access control list (ACL a wider range of IP addresses to access (for instance, your entire management subnet).

Router(config)#line vty 4 Router(config-line)#exec-timeout 5 0 Router(config-line)#password password Router(config-line)#login

Router(config-line)#transport input protocol Router(config-line)#access-class 99 in Router(config)#access-list 99 permit host adminIP Router(config)#access-list 99 deny any log

Continue reading here: Setting Up Usernames

Was this article helpful?

0 0