Tech Tip: Router Access Control

If you want to control what information hosts can telnet to or from a router, use the IP ACCESS­CLASS command. Build a standard IP access list to define which IP addresses will be allowed, then apply the list to the console or vty line.

Using the 'ip access­class 1 in' command limits inbound access to only those hosts allowed by standard IP access list 1. Conversely, using 'ip access­class 2 out' enables users on the router or access server to telnet only to those hosts whose IP addresses are allowed by standard IP access list 2. Note the difference in using IP ACCESS­CLASS to control telnet and IP ACCESS­GROUP to filter data packets.

Volume 3, Number 1 Table Of Contents


Copyright © Chesapeake 1997