Common System Operations : Using Basic ACL Rules to Control User Login

Created Apr 14, 2016 15:10:33Latest reply Apr 14, 2016 15:14:47 1117 1 0 0

After logging in to a device using Telnet or STelnet, you can configure ACL rules to allow only users with the specified IP addresses or on the specified network segments can log in to the device.

NOTE:

The Telnet protocol will bring risks to network security. The STelnet V2 mode is recommended.

The following operation assumes that the user logs in to the device using Telnet or STelnet.

# Configure rules in ACL 2005 to allow only the user at 192.168.1.5 and users on network segment 10.10.5.0/24 to log in to the VTY interfaces 0 to 4.

<HUAWEI> system-view
[HUAWEI] acl 2005
[HUAWEI-acl-basic-2005] rule permit source 192.168.1.5 0   //Allow only the user at 192.168.1.5 to log in to the device.
[HUAWEI-acl-basic-2005] rule permit source 10.10.5.0 0.0.0.255   ////Allow only users on the network segment 10.10.5.0/24 to log in to the device.
[HUAWEI-acl-basic-2005] quit
[HUAWEI] user-interface vty 0 4
[HUAWEI-ui-vty0-4] acl 2005 inbound
[HUAWEI-ui-vty0-4] quit

 

 

  • x
  • convention:

user_1763575     Created Apr 14, 2016 15:14:47 Helpful(0) Helpful(0)

Thanks!
  • x
  • convention:

Responses

Reply
You need to log in to reply to the post Login | Register

Notice:To ensure the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but not limited to politically sensitive content, content concerning pornography, gambling, drug abuse and trafficking, content that may disclose or infringe upon others' intellectual properties, including commercial secrets, trade marks, copyrights, and patents, and personal privacy. Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see“ Privacy Policy.”
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Fast reply Scroll to top