Telnet Session Timeouts

Setting the login and enable passwords might not provide enough security in some cases. The timeout for an inactive Telnet session (10 minutes by default) provides an additional security measure. If the console is left unattended in privileged mode, any user can modify the router's configuration. You can change the login timeout via the exec-timeout mm ss command, where mm is minutes and ss is seconds. The commands in Example 8-14 show what happens before, during, and after changing the timeout to 60 minutes and 0 seconds.

Example 8-14 Changing the Login Timeout: Before, During, and After

! BEFORE

line vty 0 4

password 7 01070916490E081B logging synchronous login

! DURING

Zion#conf t

Enter configuration commands, one per line. End with CNTL/Z. Zion(config)#line vty 0 4 Zion(config-line)#exec Zion(config-line)#exec-Zion(config-line)#exec-t Zion(config-line)#exec-timeout ? <0-35791> Timeout in minutes

Zion(config-line)#exec-timeout 60 ? <0-2147483> Timeout in seconds <cr>

continues

Zion(config-line)#exec-timeout 60 ? <0-2147483> Timeout in seconds <cr>

continues

496 Chapter B: Managing and Securing OSPF Networks

Example 8-14 Changing the Login Timeout: Before, During, and After (Continued)

Zion(config-line)#exec-timeout 60 0 Zion(config-line)#~Z Zion# ! AFTER line vty 0 4 exec-timeout 60 0 password 7 01070916490E081B login ! !

The exec-timeout command is useful, not only from a security standpoint but also from a network management standpoint. To clarify, if a Telnet session is not closed properly, the router still considers that session to be open although no activity is occurring. When a Telnet session is considered open, it reduces the total possible vty sessions (5 maximum); eventually you could inadvertently lock yourself out of the router. As a result, you must reboot the router or gain access via the console port to disconnect these "ghost" sessions. However, if you configure all ports (console, line vty, and aux) with the exec-timeout command, after 60 minutes and 0 seconds (as specified in the Example 8-14), the router disconnects the session for inactivity.

Continue reading here: Password Encryption

Was this article helpful?

0 0