Re: me

From
Ilya V. Kotlyarov (2:5020/400)
To
Eugene Grosbein (2:5054/37.63)
Date
2009-06-11T11:37:38Z
Area
RU.CISCO
From: "Ilya V. Kotlyarov" <hacki@bofh.org.ru>

On Thu, 11 Jun 2009 13:28:05 +0400
Eugene Grosbein <Eugene.Grosbein@f1.n5006.z2.fidonet.org> wrote:

EG> Привет!
EG> 
EG> Напомните, можно ли на цискороутер с кучей vlan-ов навесить ACL
EG> по запрету telnet-коннектов (кроме одной IP-сети) так, чтобы
EG> не дублировать эти правила в собственных ACL каждого vlan-а?

На vty вешать.

line vty 0 4
access-class xx in

access-list xx permit сетка
access-list xx deny any

-- 
*/Another call solved by the helpdesk from hell...
--- ifmail v.2.15dev5.4
 * Origin: RTComm.RU (2:5020/400)
SEEN-BY: 50/204 450/1024 461/43 640 465/11 469/142 999 4625/8 4641/444
SEEN-BY: 5000/5000 5006/1 5007/1 5010/70 5011/13 5012/46 5015/28 5019/26
SEEN-BY: 5020/175 400 545 982 1521 2238 4441 5021/29 5025/3 5026/14 5027/12
SEEN-BY: 5030/1080 5034/13 5035/38 5036/1 5037/28 5045/7 5049/1 5054/1 4 8 9
SEEN-BY: 5054/28 30 36 37 67 75 81 89 5060/88 5061/15 5062/10 5063/3 5066/18
SEEN-BY: 5075/5 35 5077/70 5080/68 5084/9 5085/13 5095/20 5096/18 6001/10
SEEN-BY: 6004/3 6009/3
PATH: 5020/400 545 5054/1 37