Secure Access Cisco 2950/Help with Commands

Posted on 2007-08-02
Last Modified: 2008-01-09
Hello Experts,

I would like to Secure my newly configured 2950 Switch and wanted to lock it down. The needs are:

(1)Limit the remote access to One Ip address
(2) Password Protect the Telnet console/Potentiall use SSH
(3)Encrypt As much as the passwords as possible

Thanks in Advance experts
Question by:Atomicsteaks
    LVL 27

    Expert Comment

    LVL 1

    Accepted Solution

    For all of this you will need to make sure you have an IOS image with CRYPTO

    (1)Limit the remote access to One Ip address
    (2) Password Protect the Telnet console/Potentiall use SSH

    Create an access list such as:

    ip access-list extended VTYAccess
         permit tcp host any eq 22 log (where is the host you want to access from)
         deny ip any any

    Then apply this to the VTY interfaces and specify SSH only

    line vty 0 4 (or 0 15 to hit all of them)
        transport input ssh
        access-class VTYAccess in

    (3)Encrypt As much as the passwords as possible

    Using SSH you will need to set up encryption on the switch

    If you need any further explanation please let me know.

    crpto key gen rsa

    select the strength and it will create the key

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Suggested Solutions

    This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
    I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now