Accessing a Cisco Security Appliance with Telnet

You can manage Security Appliance by using Telnet from hosts on any internal interface. With Internet Protocol Security (IPSec) configured, you can use Telnet to administer the console of a Cisco Security Appliance remotely from lower-security interfaces.

To access the Security Appliance using a Telnet connection, you have to first configure the PIX Firewall for Telnet access:

Step 1 Enter the PIX Firewall telnet command: telnet local-ip [mask] [if-name]

You can identify a single host or a subnet that can have Telnet access to the Security Appliance. For example, to let a host on the internal network with an address of 10.1.1.24 access the PIX Firewall, enter the following:

telnet 10.1.1.24 255.255.255.255 inside

NOTE If you do not specify the interface name, the telnet command adds command statements to the configuration to let the host or network access the Telnet management session from all internal interfaces.

Step 2 Configure the Telnet password using the password command: password telnetpassword

If you do not set a password, the default Telnet password is cisco. NOTE The passwd command can be used interchangeably with the password command.

Step 3 If required, set the duration for how long a Telnet session can be idle before the Security Appliance disconnects the session. The default duration is 5 minutes. To configure the timeout for 15 minutes, you would enter the following:

telnet timeout 15

Step 4 (Optional) To protect access to the console with an authentication server, use the aaa authentication telnet console command. (Authentication, authorization, and accounting [AAA] authentication is optional.) This requires that you have a username and password on the authentication server or configured locally on the firewall. When you access the console, the Security Appliance prompts you for these login credentials. If the authentication server is offline, you can still access the console by using the username pix and the password set with the enable password command.

Step 5 Save the commands in the configuration using the write memory command.

As soon as you have Telnet configured on Cisco Security Appliance, you are ready to access the Security Appliance using a Telnet session. You can start a Telnet session to the Security Appliance from the Windows command-line interface (CLI).

Continue reading here: Creating a Boothelper Disk Using a Windows PC

Was this article helpful?

0 0