Got it

SSH login

Created: Jun 30, 2020 12:54:32Latest reply: Jun 30, 2020 13:05:01 302 1 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi,

The customer has configured  ACL to restrict users to log in the switch S6700 V200R019C10. However, users in the IP addresses can still set up SSH connections with the switch and the user name and password can be normally input. 


Key configurations are as follows: 

acl 2000 

rule 5 permit source 10.xxx.xxx.0 24 

rule 999 deny ip 

user-interface vty 0 4 

acl 2000 inbound 

authentication-mode aaa 

protocol inbound ssh 

#


Symptom: 

[S6700] stelnet 10.xxx.xxx.2 

Trying 10.xxx.xxx.2 

Press CTRL + K to abort 

Connected to 10.xxx.xxx.2 

Please input the username: test 

Enter password: 


info: The connection was closed by remote host.


Featured Answers
Popeye_Wang
Admin Created Jun 30, 2020 13:05:01

Hi,

After the acl xxxx inbound command is configured in the VTY user interface view. When the IP addresses that are not allowed by the ACL log in to the device, the command can not prevent the device from displaying the user and entering the password.

There are two solutions. 

1. Configure the ACL on the SSH server.

   ssh server acl 2000 

2.Limiting traffic on the interface

traffic classifier Deny_SSH 

if-match acl 2000 

traffic behavior Deny_SSH 

quit 

traffic policy Deny_SSH 

classifier Deny_SSH behavior Deny_SSH 

quit 

interface Gx/x/x

traffic-policy Deny_SSH inbound 

#


View more
  • x
  • convention:

All Answers

Hi,

After the acl xxxx inbound command is configured in the VTY user interface view. When the IP addresses that are not allowed by the ACL log in to the device, the command can not prevent the device from displaying the user and entering the password.

There are two solutions. 

1. Configure the ACL on the SSH server.

   ssh server acl 2000 

2.Limiting traffic on the interface

traffic classifier Deny_SSH 

if-match acl 2000 

traffic behavior Deny_SSH 

quit 

traffic policy Deny_SSH 

classifier Deny_SSH behavior Deny_SSH 

quit 

interface Gx/x/x

traffic-policy Deny_SSH inbound 

#


View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.