I'm playing with routers and serial interfaces in my home lab while studying for an exam. I've got two routers using PPP with CHAP authentication to successfully connect, but having defined the username of the opposite router and the password they have in common I can SSH in to manage the routers with those credentials. I have tried one set of alternate privileges (username otherrouter privilege 0 password password) but that didn't help.
Obviously any in-production router that's authenticating to a service provider would have ACLs restricting vty access, but I'd still like to deny usernames that aren't intended for management to be able to ssh or telnet in from the internal side, if it's possible.
Sorry for the simpleton question, I've been trying to use print and web resources to find an answer but apparently I don't know how to ask the question right... Any suggestions for further reading on the topic would be appreciated.