11-11-2013 11:19 AM - edited 03-07-2019 04:32 PM
I have an ACL on my vty port(s)
ip access-list standard vty-access
permit 192.168.199.3
permit 172.25.0.0 0.0.255.255
permit 192.168.198.0
permit any
I need to edit this and take out the "permit any" --I also need to add some hosts
If I ssh into the device (it is remote) and try to change the ACL, it won't let me!
I can type in
no permit any
but that statement re-appears.
If I add some hosts, they don't show up.
What could be the issue here?
Solved! Go to Solution.
11-11-2013 01:37 PM
A log of what you have done would really help to see what goes wrong.
How it works in general:
1) Do a "sh ip access-list vty-access"
You see the sequence-numbers in front of the ACEs.
2) Go int to the ACL "ip access-list standard vty-access"
There you can do a "no XX" where XX is the sequence-number or add new ACEs.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
11-11-2013 01:37 PM
A log of what you have done would really help to see what goes wrong.
How it works in general:
1) Do a "sh ip access-list vty-access"
You see the sequence-numbers in front of the ACEs.
2) Go int to the ACL "ip access-list standard vty-access"
There you can do a "no XX" where XX is the sequence-number or add new ACEs.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
11-11-2013 02:03 PM
What error Message you are getting when you add a new hosts ??
As far as I belive , you may not be able to add/permit new hosts as you said "permit any" is already there ( on standard list ) as advised earlier you can either do a "no XX" where XX is the sequence-number , or no permit any
If you are still not getting that option , what version of code you are using ??
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide