Как включить telnet cisco

от admin

CONFIGURE TELNET ON SWITCH (in Cisco Packet Tracer)

Telnet is a protocol by which you can remotely login into remote devices to make changes in the configuration of that device. The aim of this article is to give you a quick guide about how you can enable telnet on a switch.

STEP BY STEP GUIDE:

STEP 1: OPEN CISCO PACKET TRACER

STEP 2: MAKE CONNECTIONS

As shown in the figure below, go to (1) End Devices and select (2) PC and then finally drag and drop PC on Screen.

Then select a switch [ I have taken Switch named as 2950–24]. Go to (1)Network device ->(2) switches ->(3) 2950–24 as shown in the figure below.

Then finally take a wire and connect PC to switch.

Now when you have taken the PC, wire, switch then start making the connection as shown in the figure below.

Note: The green triangle might be appearing as an orange circle when you have just made the connections, but don’t worry after some time they will become green.

STEP 3: ADD IP ADDRESS TO PC

Click on the PC and then a dialogue box will appear. Go to Desktop then click IP Configuration button.

A dialogue box will open up and then fill the IP address of PC whatever you want to, For e.g. write 10.0.0.1 in IP address field and then automatically subnet mask will be filled as 255.0.0.0.

STEP 4: ENABLE TELNET ON SWITCH

Now close the dialogue box and select switch now and then a dialogue box will be opened for the switch and then select CLI where we will have to write the main commands to do telnet configuration on the switch.

Now hit enter and start writing commands on CLI. Write the commands highlighted in yellow colour as shown in the figure below.

In case the image is not visible, the commands that you have to write are:

en

conf t

int vlan 1

no shut

ip add 10.0.0.10 255.0.0.0

exit

line vty 0 4

password cisco

login

exit

enable secret cisco12

After you are done writing all the commands then it means you have successfully enabled telnet on the switch. A brief explanation of these commands is given at last of this article.

STEP 5: CHECK IF TELNET IS ENABLED OR NOT?

Now to test it go to pc and then select command prompt.

After opening the command prompt, write

It will ask you for a password and then you need to write

We are writing cisco as it is the password we have given, this is just an example, hence if you have given some other password, then write that. Also, when you will type cisco you will see nothing happening on the keyboard. So, don’t worry it is how the command prompt works when the user is typing a password. So, after you are done typing password and though nothing seems to be written just press enter. Only if you have filled correct password, it will work.

After successfully entering the password, now you are able to remotely login into the switch using telnet. Due to which you will see the following coming on command prompt.

Then type en which means enable and enter the password as cisco12. Now you are done and experiment has been completed. The following image of PC dialogue box shows what you have to write in command prompt.

DOWNLOAD THIS LAB EXPERIMENT

If you want to download this experiment and run it on your cisco packet tracer, click me to visit that .pkt file. After the link opens you will see a download button as shown in the figure below from where you can download the experiment and run it on your Packet tracer.

Explanation of commands used:

  1. en means to enable and is used to enter into privileged mode and you will see after typing en the symbol > will become to #. The symbol > indicates you are in user mode and # means you are in privileged mode. In privileged mode, you get more powers which you don’t get in user mode Like in this # mode you can see more detailed information about configuration, copy that configuration, etc. However, the limitation is that you cannot make any change to global parameters. So, in order to do that type conf t.

2. conf t is for configuring terminal and after typing it you enter into global configuration mode where you have the powers to change global parameters which you don’t have in privileged mode.

3. int vlan 1: Here int means interface. int vlan means interface VLAN which gives your switch a routable interface. This then allows you to assign ip address to the interface so the switch can be managed over the network. You can read more about it on Wikipedia.

4. no shut or no shutdown is just to enable an interface or say to turn it up. It is a very simple command to turn on the interface.

5. ip add 10.0.0.10 255.0.0.0 command is for giving IP address to VLAN interface, think it as the switch has now an IP 10.0.0.10 whose subnet mask is 255.0.0.0.

6. line vty 0 4 means you are assigning 5 virtual terminal connections to the virtual port. These virtual connections, in this case, are for telnet and 0–4 is the range. If we write line vty 0 15 then it will mean 16 virtual connections are allowed. This command is basically used to get telnet access to the device.

7. password cisco command means that we are setting the password as cisco. You can keep the password as anything. Writing cisco here is just an example. If you think line vty as a door to enter switch here then the password is the key to that door. Unless you don’t write the correct password you will have no right to access the switch.

8. login command is just to ensure that when you try to remotely access the switch using telnet protocol then it must ask for a password. It is just ensuring that your door i.e. line vty is locked and anyone trying to open that door needs a key i.e. password to open it.

9. enable secret cisco12 command is you need to access the privileged mode. Earlier by simply writing en, you were able to enter privileged mode. But now after writing this command you need to enter password first to enter the privileged mode. Here the password set is cisco12. You can write anything in place of cisco12. Also, secret means that your password will be stored in encrypted form and hence is more secure.

Thank you for reading this far!

There is a list of lab experiments performed on cisco packet tracer which you can visit by clicking me. If the repository is helpful then please don’t forget to star it and fork it, also if this article was helpful then please do give it a clap.

Сети для самых маленьких. Часть первая (которая после нулевой). Подключение к оборудованию cisco

Тематику cisco на хабре нельзя назвать популярной, зачастую интересные статьи остаются почти незамеченными. Но нас приятно удивил ажиотаж вокруг нашей предыдущей публикации. Больше тысячи человек добавили её в избранное, и это определённо говорит о том, что продолжение необходимо.
Кроме того, много людей, имеющих опыт реального планирования и строительства сетей, делали очень правильные замечания по резервированию. Дело в том, что предложенная в прошлый раз схема сети — это макет, лаборатория, на который мы будем отрабатывать и понимать технологии, поэтому такими вещами мы не озадачивались. В реальной же жизни, особенно, если вы оператор связи/провайдер, необходимы различные схемы резервирования: VRRP, STP, Link Aggregation, протоколы динамической маршрутизации.
Все замечания мы постараемся учесть и в конце цикла, вероятно, рассмотрим то, как сеть должна строиться, чтобы через полгода после запуска инженеру не было мучительно больно.

Сегодня же мы обратимся к части немного скучной, но важной для начинающих: как подключиться, поставить или сбросить пароль, войти по telnet. Также рассмотрим существующие программы — эмуляторы ciscо и интерфейс оборудования.
Как и обещали, в этот раз всё по-взрослому: с видео.

Среда

Начнём с того, в какой среде будем работать.

В данный момент есть два известных пакета программ, позволяющих моделировать сеть, построенную на оборудовании Cisco:

а) Цисковский же продукт Packet Tracer, который по идее свободно не распространяется. Это эмулятор и имеет лишь некоторые функции Cisco IOS. Вообще говоря, он сильно ограничен и многие вещи в нём реализованы лишь отчасти. Никаких тонких настроек. С другой стороны к настоящему моменту версия 5.3.2 поддерживает создание GRE-туннелей, протоколов динамической маршрутизации (и в их числе даже BGP!). Притом он очень прост в освоении и имеет в своём арсенале сервера (FTP, TFTP, DHCP, DNS, HTTP, NTP, RADIUS, SMTP, POP3), рабочие станции и свичи. Сейчас уже есть под Linux, хотя в былые времени он прекрасно запускался и из-под Wine.

б) Распространяемый по лицензии GNU GPL симулятор GNS3. В этом пакете необходимо загружать настоящие образы Cisco IOS. С одной стороны это плюс – вы работаете с настоящим интерфейсом cisco и ограничены лишь своей фантазией, существующими стандартами и производительностью рабочей станции, с другой, во-первых, эти IOS ещё нужно суметь достать, во-вторых, это более сложный продукт для понимания, и в-третьих, в нём есть только маршрутизаторы и «типа» коммутаторы.

Я считаю, что для знакомства с принципами лучше начать всё же с Packet Tracer’a, а потом переходить на тяжёлую артиллерию по мере надобности. Все мы не дети малые, где взять то, что нам нужно, рассказывать не будем.

Способы подключения

  • Telnet/ssh
  • Терминальное подключение с рабочей станции через консольный кабель
  • Web-интерфейс (Cisco SDM).

Последний вариант даже не упоминайте в приличном обществе. Даже если вы адепт мыши и браузера, очень не советую.
На своём примере при работе с другим оборудованием я сталкивался с тем, что настроенное через веб не работает. Хоть ты тресни, но не работает. А у того же длинка вообще был баг в одной версии прошивки для свичей: если изменить настройки VLAN в веб-интерфейсе из под линукс, то свич становится недоступным для управления. Это официально признанная проблема).Телнет – стандартная, всем известная утилита, как и ssh. Для доступа к cisco по этим протоколам нужно настроить пароли доступа, об этом позже. Возможность использования ssh зависит от лицензии IOS.

Управление по консоли

Ну вот принесли вы маршрутизатор, распечатали, питание на него дали. Он томно зашумел кулерами, подмигивает вам светодиодами своих портов. А чего дальше-то делать?
Воспользуемся один из древнейших и нестареющих способов управления практически любым умным устройством: консоль. Для этого вам нужен компьютер, само устройство и подходящий кабель.
Тут каждый вендор на что горазд. Какие только разъёмы они не используют: RJ-45, DB-9 папа, DB-9 мама, DB-9 с нестандартной распиновкой, DB-25.
У циски используется разъём RJ-45 на стороне устройства и DB-9 мама (для подключения к COM-порту) на стороне ПК.
Консольный порт выглядит так:

Консольный порт cisco

Всегда выделен голубым цветом. С недавних пор стало возможным управление по USB.
А это консольный кабель cisco:

Консольный кабель cisco

Раньше он поставлялся в каждой коробке, теперь зачастую стоит отдельных денег. В принципе подходит аналогичный кабель от HP.
Проблема в том, что современные ПК зачастую не имеют COM-порта. На выручку приходят частоиспользуемые конвертеры USB-to-COM:

Либо редкоиспользуемые для этих целей конвертеры RS232-Ethernet

После того, как вы воткнули кабель, определили номер COM-порта, для подключения можно использовать Hyperterminal или Putty в Виндоус и Minicom в Линукс.

Управление через консоль доступно сразу, а вот для телнета нужно установить пароль. Как это сделать?
Обратимся к PT.
Начнём с создания маршрутизатора: выбираем его на панели внизу и переносим на рабочее пространство. Даём какое-нибудь название

c2811

Что бы вы делали, если бы это был самый взаправдашний железный маршрутизатор? Взяли бы консольный кабель и подключились им в него и в компьютер. То же самое сделаем и тут:

Packet tracer consolePacket tracer console

Кликом по компьютеру вызываем окно настройки, в котором нас интересует вкладка Desktop. Далее выбираем Terminal, где нам даётся выбор параметров

Впрочем, все параметры по умолчанию нас устраивают, и менять их особо смысла нет.

Если в энергонезависимой памяти устройства отсутствует конфигурационный файл (startup-config), а так оно и будет при первом включении нового железа, нас встретит Initial Configuration Dialog prompt:

cisco interface

Вкратце, это такой визард, позволяющий шаг за шагом настроить основные параметры устройства (hostname, пароли, интерфейсы). Но это неинтересно, поэтому отвечаем no и видим приглашение

Это стандартное совершенно для любой линейки cisco приглашение, которое характеризует пользовательский режим, в котором можно просматривать некоторую статистику и проводить самые простые операции вроде пинга. Ввод знака вопроса покажет список доступных команд:

Грубо говоря, это режим для сетевого оператора, инженера первой линии техподдержки, чтобы он ничего там не повредил, не напортачил и лишнего не узнал.
Гораздо большие возможности предоставляет режим с говорящим названием привилегированный. Попасть в него можно, введя команду >enable. Теперь приглашение выглядит так:

Здесь список операций гораздо обширнее, например, можно выполнить одну из наиболее часто используемых команд, демонстрирующую текущие настройки устройства ака “конфиг” #show running-config. В привилегированном режиме вы можете просмотреть всю информацию об устройстве.

Прежде, чем приступать к настройке, упомянем несколько полезностей при работе с cisco CLI, которые могут сильно упростить жизнь:

— Все команды в консоли можно сокращать. Главное, чтобы сокращение однозначно указывало на команду. Например, show running-config сокращается до sh run. Почему не до s r? Потому, что s (в пользовательском режиме) может означать как команду show, так и команду ssh, и мы получим сообщение об ошибке % Ambiguous command: «s r» (неоднозначная команда).

— Используйте клавишу Tab и знак вопроса. По нажатию Tab сокращенная команда дописывается до полной, а знак вопроса, следующий за командой, выводит список дальнейших возможностей и небольшую справку по ним (попробуйте сами в PT).

— Используйте горячие клавиши в консоли:

Ctrl+A — Передвинуть курсор на начало строки
Ctrl+E — Передвинуть курсор на конец строки
Курсорные Up, Down — Перемещение по истории команд
Ctrl+W — Стереть предыдущее слово
Ctrl+U — Стереть всю линию
Ctrl+C — Выход из режима конфигурирования
Ctrl+Z — Применить текущую команду и выйти из режима конфигурирования
Ctrl+Shift+6 — Остановка длительных процессов (так называемый escape sequence)

— Используйте фильтрацию вывода команды. Бывает, что команда выводит много информации, в которой нужно долго копаться, чтобы найти определённое слово, например.
Облегчаем работу с помощью фильтрации: после команды ставим |, пишем вид фильтрации и, собственно, искомое слово(или его часть). Виды фильтрации (ака модификаторы вывода):

begin — вывод всех строк, начиная с той, где нашлось слово,
section — вывод секций конфигурационного файла, в которых встречается слово,
include — вывод строк, где встречается слово,
exclude — вывод строк, где НЕ встречается слово.

Но вернемся к режимам. Третий главный режим, наряду с пользовательским и привилегированным: режим глобальной конфигурации. Как понятно из названия, он позволяет нам вносить изменения в настройки устройства. Активируется командой #configure terminal из привилегированного режима и демонстрирует такое приглашение:

В режиме глобальной конфигурации не выполняются довольно нужные порой команды других режимов (тот же show running-config, ping, etc.). Но есть такая полезная штука, как do. Благодаря ей мы можем, не выходя из режима конфигурирования, выполнять эти самые команды, просто добавляя перед ними do. Примерно так:

Настройка доступа по Telnet

Из этого-то режима мы и настроим интерфейс для подключения компьютера через telnet:
Команда для перехода в режим конфигурации интерфейса FastEthernet 0/0:

По умолчанию все интерфейсы отключены (состояние administratively down). Включаем интерфейс:

shutdown — означает “выключить интерфейс”. Соответственно, если вы хотите отменить действие команды, то используйте слово no перед ней. Это правило общее для CLI и применимо к большинству команд.

Подключаемся. Для этого надо использовать кроссоверный кабель. (Хотя в реальной жизни это зачастую уже необязательно – все карточки умеют понимать приём/передачу, однако встречаются ещё маршрутизаторы, порты которых не поднимаются при использовании неправильного типа кабеля — так что будьте внимательны)

crossover cable
Настраиваем IP-адрес компьютера через Desktop.

IP адрес

И пробуем подключиться, выбрав Command Prompt в панели Desktop:

Packet Tracer telnet

Как и ожидалось, циска не пускает без пароля. В реальной жизни обычно выдаёт фразу “Password required, but none set”

Пароли

Подключение по telnet или ssh называется виртуальным терминалом (vt) и настраивается следующим образом:

0 4 — это 5 пользовательских виртуальных терминалов=telnet сессий.
Этого уже достаточно, чтобы попасть в пользовательский режим, но недостаточно для привилегированного:

Packet Tracer telnet

Настроим пароль для enable-режима:

Packet Tracer

Чем отличается secret от password? Примерно тем же, чем ssh от telnet. При настройке secret пароль хранится в зашифрованном виде в конфигурационном файле, а password – в открытом. Поэтому рекомендуется использование secret.
Если вы всё-таки задаёте пароль командой password, то следует применить так же service password-encryption, тогда ваш пароль в конфигурационном файле будет зашифрован:

Немного об этом можно почитать здесь. Ну или чуть более по-русски, тут.

Хотим обратить ваше внимание:
сейчас принятно настраивать доступы не через виртуальные терминалы, а командами #username и #aaa new-model. В версии PT 5.3.2 они уже есть и вполне работают.
Для этого нужно выполнить:

Первая команда служит для активации новой модели

Privilege Level

Ещё один важный момент, которому в статьях уделяют мало внимания: privelege level.
Как понятно из латинского звучания — это уровень прав пользователя. Всего существует 16 уровней: 0-15.
privilege level 0 — это команды disable, enable, exit, help и logout, которые работают во всех режимах
privilege level 1 — Это команды пользовательского режима, то есть как только вы попадаете на циску и увидите приглашение Router> вы имеете уровень 1.
privilege level 15 — Это команды привилегированного режима, вроде, как root в Unix’ах

Пример1

После входа на маршрутизатор при такой настройке вы сразу увидите Router# со всеми вытекающими правами.

Все уровни со 2 по 14 настраиваются вручную. То есть, например, вы можете дать добро пользователю с privelege level 2 на выполнение команды show running-config

Пример2

Настроить права для конкретного пользователя поможет уже упомянутая прежде команда username

В первой строке назначаем уровень прав пользователю, во второй команду, разрешенную для этого уровня, в третьей задаём пароль для входа в привилегированный режим с этим уровнем.

После этого из пользовательского режима вы можете выполнить команду enable 2 и введя пароль l2poorpass попасть в привилегированный режим, в котором будут доступны все команды уровня 1 + команды уровня 2.

Для чего это может быть нужно? В российских реалиях практически ни для чего, потому что обычно на устройство нужно заходить инженерам сразу с полными правами. Ну разве что 15-й уровень ставят, чтобы двойную аутентификацию не проходить. А все другие уровни опять же для того, чтобы персонал младшего состава (техподдержка, например) мог зайти и промониторить какие-то параметры или настроить некритичную функцию.

Нельзя не упомянуть о том, что telnet — протокол незащищённый и передаёт пароль и данные в открытом виде. С помощью любого анализатора пакетов можно вычислить пароль.
Поэтому крайне рекомендуем использовать ssh — любые устройства cisco с не самой урезанной прошивкой способны выступать ssh-сервером.
Следующий набор команд позволит вам включить ssh и отключить доступ по telnet:

Имя хоста должно отличаться от Router, обязательно должно быть задано имя домена. Третьей строкой генерируется ключ и далее разрешается только ssh. Длина ключа должна быть более 768 бит, если вы желаете использовать ssh версии 2, а вы желаете этого. Всё.

Ещё одно финальное внимание новичкам: не забывайте о команде write memory — это сохранение текущей конфигурации. Впрочем, достаточно два раза обжечься, забыв сохранить, чтобы навсегда заработать иммунитет к этому — кто кодил по ночам или писал курсовую, тот поймёт.

Используя PT, мы будем настраивать оборудование не через терминал или телнет, а непосредственно через CLI устройства, которое вызывается кликом по иконке роутера — так удобнее:

CLI

Ну и на сладенькое: сброс пароля

Так, а что же делать, если на стол легла вам бушная циска с неизвестным паролем или вы очень невовремя забыли его? Вообще-то это многократно описано и легко гуглится, но повторить это необходимо.
Практически на любом сетевом устройстве есть возможность сбросить пароль, имея физический доступ. Если сделать это невозможно или это отдельная платная услуга, то скорее всего в ваших руках находится какая-то русская поделка (не в обиду, конечно, нашим производителям, но дважды я такие строки читал в документации:))
Итак, cisco:
1) Подключаетесь к устройству консольным кабелем,
2) Отправляете его в ребут (хоть по питанию, хоть командой #reload)
3) Когда на экране побежит такая строчка ########. ###, означающая загрузку образа (40-60 секунд после включения), необходимо отправить сигнал Break. Как это сделать в разных программах читать тут. Вы попадаете в режим ROMMON.
4) В этом режиме введите команду: confreg 0x2142, она заставит устройство игнорировать startup-config при загрузке.
5) Введите reset для перезагрузки
6) После загрузки running-config будет девственно чистым, а startup-config содержит по-прежнему последнюю сохранённую конфигурацию. Сейчас самое время поменять пароль или слить конфиг.
7) Самое важное: верните обратно регистры:

Если вы этого не сделаете, то вся ваша конфигурация будет актуальна до первого ребута) И хорошо, если это устройство стоит рядом, и вы вспомните, что накосячили. Мне не повезло)

В следующей статье мы обратимся к вланам и локальной сети. Обязательно к прочтению:
OSI.
VLAN

Незарегистрированные читатели Хабрахабра могут задать свои вопросы в ЖЖ.
Хочу поблагодарить пользователя thegluck за помощь в написании этой статьи.

Terminal Services Configuration Guide, Cisco IOS XE Release 16.x

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Book Title

Terminal Services Configuration Guide, Cisco IOS XE Release 16.x

Configuring Dial-In Terminal Services

View with Adobe Reader on a variety of devices

Results

Chapter: Configuring Dial-In Terminal Services

Configuring Dial-In Terminal Services

This chapter describes how to configure support for asynchronous character stream calls running Telnet, rlogin, local-area transport (LAT), XRemote, or TN3270. It includes the following main sections:

  • Dial-In Terminal Service Overview
  • Configuring Telnet and rlogin
  • Telnet and rlogin Configuration Task List
  • Using Cisco DialOut for Telnet Connections
  • Connecting a VMS Host Using LAT
  • LAT Configuration Task List
  • Monitoring and Maintaining LAT Connections
  • LAT Configuration and Connection Examples
  • Configuring TN3270
  • TN3270 Configuration Task List
  • TN3270 Configuration and Connection Examples
  • Configuring XRemote
  • XRemote Configuration Task List
  • XRemote Configuration and Connection Examples

For a complete description of the dial-in terminal services commands in this chapter, refer to the Cisco IOS Terminal Services Command Reference. To locate documentation of other commands that appear in this chapter, use the command reference master index or search online.

Dial-In Terminal Service Overview

Inbound asynchronous character stream calls are routed to virtual terminal lines and virtual asynchronous interfaces, which are used to terminate incoming character steams that do not share a physical connection with the access server or router (such as a physical interface). A virtual asynchronous interface is the place where inbound Telnet, LAT, V.120, TN3270, and packet assembler/disassembler (PAD) calls or sessions terminate on the router. Virtual terminal lines are used for attaching to the router in a nonphysical way.

Configuring support for terminal service connections means enabling network devices running the same protocol to connect across a LAN or WAN through network and terminal-emulation software.

The following sections describe how to configure these supported dial-in terminal services:

  • Configuring Telnet and rlogin—Of all protocol suites, TCP/IP is the most widely implemented on networks of all media types. TCP/IP is the current standard for internetworking and is supported by most computer vendors, including all UNIX-based workstation manufacturers. TCP/IP includes Telnet and rlogin.
  • Connecting a VMS Host Using LAT—The proprietary LAT terminal connection protocol from Digital Equipment Corporation used with Digital minicomputers.
  • Configuring TN3270—IBM 3278 terminal emulation provides TN3270-based connectivity to IBM hosts over serial lines.
  • Configuring XRemote—The X Window Systems terminal protocol from Network Control Devices, Inc., provides network functionality to remote X terminals.

Each section provides examples of how to configure and connect to a terminal service.

Configuring Telnet and rlogin

Telnet and rlogin are protocols that enable TCP/IP connections to a host. Telnet, a virtual terminal protocol that is part of the TCP/IP protocol suite, is the more widely used protocol. The rlogin protocol is a remote login service developed for the Berkeley Software Distribution (BSD) UNIX system. It provides better control and output suppression than Telnet, but can only be used when the host (typically, a UNIX system) supports rlogin. The Cisco IOS implementation of rlogin does not subscribe to the rlogin “trusted host” model. That is, a user cannot automatically log in to a UNIX system from the router, but must provide a user ID and a password for each connection.

Telnet allows a user at one site to establish a TCP connection to a login server at another site, then passes the keystrokes from one system to the other. Telnet can accept either an IP address or a domain name as the remote system address. In short, Telnet offers three main services:

  • Network virtual terminal connection
  • Option negotiation
  • Symmetric connection

The Cisco implementation of Telnet supports the following Telnet options:

  • Remote echo
  • Binary transmission
  • Suppress go ahead
  • Timing mark
  • Terminal type
  • Send location
  • Terminal speed
  • Remote flow control
  • X display location

Telnet and rlogin Configuration Task List

To configure Telnet and rlogin, perform the tasks in the following sections:

  • Configuring Telnet and UNIX rlogin (Required for Service)
  • Making Telnet and UNIX rlogin Connections (Required for Making Connections)
  • Using UNIX Style Syntax for rlogin Connections (Optional)

The section “Monitoring TCP/IP Connections” later in this chapter provides tasks for maintaining TCP/IP connections.

Configuring Telnet and UNIX rlogin

To configure support for Telnet or rlogin calls, use the following commands beginning in line configuration mode.

Router(config-line)# telnet speed default-speed maximum-speed

Negotiates speeds on reverse Telnet lines.

Router(config-line)# telnet refuse-negotiations

Causes Telnet to refuse to negotiate full-duplex, remote echo requests on incoming connections.

Router(config-line)# telnet transparent

Sets line to send a RETURN (CR) as a CR followed by a NULL instead of a CR followed by a LINE FEED (LF).

Router(config-line)# telnet sync-on-break

Sets the line to send a Telnet Synchronize signal when it receives a Telnet BREAK signal.

Router(config-line)# telnet break-on-ip

Sets the line to cause the system to generate a hardware BREAK signal on the EIA/TIA-232 line that is associated with a reverse Telnet connection when a Telnet Interrupt-Process command is received on that connection.

Router(config)# ip tcp chunk-size number

In global configuration mode, optimizes the line by setting the number of characters output before the interrupt executes.

Router(config-if)# ip alias ip-address tcp-port

In interface configuration mode, assigns an IP address to the service provided on a TCP port.

Router(config)# busy-message hostname d message d

In global configuration mode, defines a message that the router displays whenever a Telnet or rlogin connection to the specified host fails.

Router(config)# login-string hostname d message [ % sec p ] [ % sec w ] [ %b ] d [ %m ] d

In global configuration mode, defines a message that the router displays whenever a Telnet or rlogin connection to the specified host succeeds.

Router(config-line)# notify

Sets up a line to notify a user that has multiple, concurrent Telnet connections when output is pending on a connection other than the current one.

Router(config-line)# refuse-message d message d

Defines a “line-in-use” message to indicate that the line is currently busy.

The telnet speed command sets the line speed to match line speeds on remote systems in reverse Telnet, on host machines hooked up to an access server or router to access the network, or on a group of console lines hooked up to the access server or router when disparate line speeds are in use at the local and remote ends of the connection. Line speed negotiation adheres to the Remote Flow Control option, defined in RFC 1080.

Читать:
Как установить manjaro linux рядом с windows 10

The telnet refuse-negotiations command suppresses negotiation of the Telnet Remote Echo and Suppress G o Ahead options.

The telnet transparent command is useful for coping with different interpretations of end-of-line handling in the Telnet protocol specification.

The telnet sync-on-break command sets the line to cause a reverse Telnet line to send a Telnet Synchronize signal when it receives a Telnet BREAK signal. The Telnet Synchronize signal clears the data path, but the line still interprets incoming commands.

Enter the telnet break-on-ip command to control the translation of Telnet Interrupt-Process commands into X.25 BREAK indications, and to work around the following situations:

  • Several user Telnet programs send a Telnet Interrupt-Process command, but cannot send a Telnet BREAK signal.
  • Some Telnet programs implement a BREAK signal that sends a Telnet Interrupt-Process command.
  • Some EIA/TIA-232 hardware devices use a hardware BREAK signal for various purposes.

When the telnet break-on-ip command is used with a correctly operating host, Cisco IOS software implements the Telnet Synchronize and Abort Output signals, which can stop output within one packet worth of data from the time the user types the interrupt character. Enter the ip tcp chunk-size command to configure a faster response to user interrupt characters. Changing the number of characters output, or chunk size, affects neither the size of the packet used nor the TCP window size, either of which would cause serious efficiency problems for the remote host and for the access server or router. Instead, the system software checks the Telnet status after the number of characters specified, causing only a relatively minor performance loss.

Use the ip alias command to configure connections to an IP address to act identically to connections made to the primary IP address of the server on the TCP port. A user trying to connect is connected to the first free line in a rotary group using the Telnet protocol.

With the login-string command options, you can set a pause, prevent a user from issuing commands during a pause, send a BREAK character, and use a percent sign (%) in the login string. The busy-message command and login-string command are only useful with two-step protocol translation sessions. For more information about protocol translation, see the chapter “Configuring Protocol Translation and Virtual Asynchronous Devices” in this publication.

For actual sample configurations on how to configure Telnet and rlogin, see the section “Telnet and rlogin Examples” later in this chapter.

Making Telnet and UNIX rlogin Connections

To provide Telnet and rlogin connection capabilities, use the following commands in EXEC mode:

Router> connect host [ port ] [ keyword ]

Router> telnet host [ port ] [ keyword ]

Logs in to a host that supports Telnet. Refer to the descriptions for the connect and telnet commands in the Cisco IOS Terminal Services Command Reference, for a list of supported keywords. 1

Router> show hosts

Displays a list of available hosts.

Router> show tcp

Displays the status of all TCP connections.

Logs out of the host by entering the default escape sequence. 2

Choose from the following list of escape sequences, according to your task:

Press Ctrl^ b if your task is to break.
Press Ctrl^ c if your task is to interrupt a process (IP).
Press Ctrl^ h if your task is to erase a character (EC).
Press Ctrl^ o if your task is to abort an output display (AO).
Press Ctrl^ t if your task is to confirm you are at the host.
Press Ctrl^ u if your task is to erase a line (EL).

Logs out of the host by entering a special escape sequence. 2 These special Telnet sequences map generic terminal control functions to operating system-specific functions.

Lists the available Telnet commands at any time during the active Telnet session. 2

Exits a Telnet or rlogin session.

1. Cisco IOS software provides a robust collection of connection options. The options allow for enhanced sessions allowing, for example, encrypted sessions, Kerberos login, and File Transfer Protocol and World Wide Web connections. Additionally, it is possible to suppress system messages, including IP addresses and server names, displayed during session connection and disconnection. This function allows transparent TCP connections and can be useful when an asynchronous tunnel connection is being made.

2. Press and hold the Ctrl and Shift keys while pressing the 6 key. You can enter the command character as you hold down the Ctrl key or with Ctrl released; you can enter the command characters as either uppercase or lowercase letters.

With the Cisco IOS implementation of TCP/IP, you are not required to enter the connect or telnet commands to establish a Telnet connection. You can just enter the learned host name as long as the host name is different from a command word for the router. Telnet must be the default (you can make it the default with the transport preferred command). Use the show hosts EXEC command to display a list of the available hosts. Use the show tcp EXEC command to display the status of all TCP connections. The Cisco IOS software assigns a logical name to each connection, and several commands use these names to identify connections. The logical name is the same as the host name, unless that name is already in use or you change the connection name with the name-connection EXEC command. If the name is already in use, the Cisco IOS software assigns a null name to the connection. For an example of making a Telnet connection, see the section “Telnet and rlogin Examples” later in this chapter.

After you enter the rlogin command, you can have several concurrent rlogin connections open and switch between them. To open a new connection, exit the current connection by entering the escape sequence (Ctrl-Shift-6 then x [ Ctrl^x ] by default) to return to the system command prompt, then open a new connection. For an example of making an rlogin connection or switching between connections, see the sections “rlogin Connection Example” or “Switch Between Telnet and rlogin Sessions Example” later in this chapter.

Note We recommend that you use Encrypted Kerberized Telnet whenever you establish a Telnet session to a router or access server, which protects the integrity of the device. For information about Encrypted Kerberized Telnet, refer to Cisco IOS Security Configuration Guide.

Using UNIX Style Syntax for rlogin Connections

The rlogin command supports the standard BSD UNIX -l option. Before this addition was introduced, the rlogin command allowed remote users to log in using the /user username option, which was not compatible with the standard UNIX rlogin -l username option.

This feature is supported on all of Cisco TCP/IP-enabled routers and access servers.

To set up this UNIX feature, use one of the following the following commands in EXEC mode:

Router# rlogin hostname

Enters the name of the host to which you are connecting.

Router# rlogin hostname [ -l hostname] [ /user hostname]

Enters the user name.

Router# rlogin hostname [ -l hostname] [ /user hostname] debug

(Optional) Enters the debug mode to troubleshoot the connection from the remote site to the host.

Router# rlogin hostname [ -l hostname] [ /user hostname] /quiet

(Optional) Enters the /quiet keyword to make a transparent connection from the remote site to the host.

When you are done with the UNIX session, use the exit command to end it.

Monitoring TCP/IP Connections

To display the status of a TCP connection or view a summary of the TCP connection endpoints in the system, use the following commands in user EXEC mode:

Router> show tcp [ line-number ]

Displays the status of a TCP connection.

Router> show tcp brief [ all ]

Displays a summary of the TCP connection endpoints in the system.

Telnet and rlogin Examples

This section provides the following examples:

  • Telnet Connection Example
  • Telnet Connection Without and With Messages Suppressed Example
  • rlogin Connection Example
  • rlogin UNIX-Style Syntax Example
  • Switch Between Telnet and rlogin Sessions Example
  • List Supported Telnet Commands Example

Telnet Connection Example

The following example establishes a telnet connection to a host named server1 and specifies vt100 as the terminal type for the session:

Router> telnet server1 /terminal-type vt100

The following example connects to a host with logical name host1:

Router> host1

Telnet Connection Without and With Messages Suppressed Example

The following examples show how to suppress the onscreen messages displayed during login and logout of a Telnet session.

The following example shows the messages displayed when a connection is made without using the optional /quiet keyword with the telnet EXEC command to suppress messages from the operating system:

Router# telnet Server3 Translating "Server3". domain server (172.18.89.42) [OK] Trying Server3—Server3.cisco.com (172.18.89.42). Open Kerberos: No default realm defined for Kerberos! login: User2 Password: Welcome to OpenVMS VAX version V6.1 on node CRAW Last interactive login on Tuesday, 15-DEC-1998 11:01 Last non-interactive login on Sunday, 3-JAN-1999 22:32 Server3) logout User2 logged out at 16-FEB-2000 09:38:27.85 [Connection to Server3 closed by foreign host] Router#

The following example shows the limited messages displayed when connection is made using the optional /quiet keyword:

Router# telnet Server3 /quiet login: User2 Password: Welcome to OpenVMS VAX version V6.1 on node CRAW Last interactive login on Tuesday, 15-DEC-1998 11:01 Last non-interactive login on Sunday, 3-JAN-1999 22:32 Server3) logout User2 logged out at 16-FEB-2000 09:38:27.85 Router#

The /quiet keyword is useful for making transparent connections during asynchronous tunnel connections. The keyword can be used with any of the EXEC connection commands— connect, telnet, and rlogin.

Note The Cisco IOS software offers the ip telnet quiet global configuration command, which also suppresses onscreen messages during Telnet connections. The ip telnet quiet command is set globally, and is useful to Internet service providers that want to permanently suppress onscreen system connection messages that often include information such as server names and IP addresses. Refer to the Cisco IOS Dial Technologies Command Reference , for more information about the ip telnet quiet command.

rlogin Connection Example

The following example makes an rlogin connection to a host at address 172.31.21.2 and enables the message mode for debugging:

Router> rlogin 172.31.21.2 debug

rlogin UNIX-Style Syntax Example

The following example illustrates how a user named jsmith can use the rlogin ? help command and the debug mode to establish and troubleshoot a remote connection to the host named Alviso:

Router> rlogin ? WORD IP address or hostname of a remote system Router> rlogin Alviso ? -l Specify remote username /user Specify remote username debug Enable rlogin debugging output <cr> Router> rlogin Alviso -l ? WORD Remote user name Router> rlogin Alviso -l jsmith ? debug Enable rlogin debugging output <cr> Router> rlogin Alviso -l jsmith debug

Switch Between Telnet and rlogin Sessions Example

You can switch between sessions by escaping one session and resuming a previously opened session. The following example shows how to escape out of a connection to the host named host1 and to resume connection 2. You escape out of the current session and return to the EXEC prompt by entering the command sequence Ctrl-Shift-6 then x. Resume the connection with the resume command.

host1% ^^X Router> resume 2

You can omit the command name and simply enter the connection number to resume that connection. The following example illustrates how to resume connection 3:

To list all the open sessions associated with the current terminal line, use the where command.

List Supported Telnet Commands Example

At any time during an active Telnet session, you can list the Telnet commands by pressing the escape sequence keys (by default Ctrl-Shift-6) followed by a question mark at the system prompt:

A sample of this list follows:

Router> ^^? [Special telnet escape help] ^^B sends telnet BREAK ^^C sends telnet IP ^^H sends telnet EC ^^O sends telnet AO ^^T sends telnet AYT ^^U sends telnet EL

Note In screen output examples that show two caret (^^) symbols together, the first caret represents the Ctrl key and the second caret represents the keystroke sequence Shift-6. The double caret combination (^^) means hold down the Ctrl key while you press the Shift and the 6 keys.

Using Cisco DialOut for Telnet Connections

The Cisco DialOut feature enables users on a workstation operating Windows to send faxes or connect to service provider services outside the LAN by using modems attached or internal to a network access server. The Cisco DialOut feature extends the functionality of Telnet by enabling users to control the activity of these modems from their desktop computers using standard communications software.

The Cisco DialOut feature has two components:

  • Telnet Extensions for Dialout—Network access server component
  • The DialOut Utility—Client/desktop component

Both components are required and neither can function as a stand-alone feature.

The Telnet Extensions for Dialout component uses reverse Telnet to access modems attached to the network access server. This component enables the network access server to interface with the client/desktop component of the Cisco DialOut feature and to return Carrier Detect signals to the communications software so that the software can determine when to start dialing a particular number.

Telnet extensions allow the communications software running on the desktop computer of the client to control modem settings such as baud rate, parity, bit size, and stop bits.

To enable this feature, you only need to configure the access server or router for reverse Telnet and configure the appropriate lines to send and receive calls.

The client/desktop component of Cisco DialOut feature must be installed on the client workstation before this feature can be used. For information about installing and using the client/desktop component of the Cisco Dial-Out feature, and configuring the access server, see the DialOut Utility User Guide Cisco publication at Cisco.com.

Configuring Stream TCP

Stream TCP connections, or raw TCP or TCP-Clear connections as they are sometimes called, are used to transport a stream of 8-bit characters as-is over an IP network, between a TCP client and TCP server system. This method is used to transport legacy asynchronous application data through an IP network, for example, with a Point-of-Sale (PoS) terminal connecting to an application server.

To establish a Stream TCP connection from an EXEC session, use the /stream keyword with the telnet command. You will also generally want to configure the line to provide for data transparency. See the following procedure for the steps to do this.

Stream TCP Autocommand Procedure

In the following procedure, a line is configured so that any connection into it is automatically connected using Stream TCP to the application server at the specified IP address and TCP port (IP address 10.1.2.3 and TCP port 4321 in the examples).

Step 1 Configure the line for data transparency using the following configuration as an example:

Router# configure terminal Router(config)# line 33 Router(config-line)# no motd-banner Router(config-line)# no exec-banner Router(config-line)# no vacant-message Router(config-line)# escape-character NONE Router(config-line)# no hold-character

Step 2 Configure the autocommand:

Router(config-line)# autocommand telnet 10.1.2.3 4321 /quiet /stream

Step 3 Configure the telnet-faststream option (this is an optional step). On platforms that support this feature such as the Cisco AS5800 access servers, you may want to configure the telnet-faststream autocommand option to provide for Stream TCP performance enhancements. An example of how this option can be entered follows:

Router(config-line)# autocommand-options telnet-faststream

Connecting a VMS Host Using LAT

Connection to a VMS host is slightly different if you are connecting to a VMS host running VMS Version 5.4 or earlier than when connecting to a VMS host running VMS Version 5.5 or later software.

VMS Version 5.4 or Earlier System

If a host-initiated connection is received that specifies a destination port number that corresponds to a virtual port on the router, a virtual EXEC process will be created to allow the user to log in. This process can be used, in conjunction with the Digital set host/dte command on VMS, to connect to a router named router1 from a VMS host node, as shown in the following example:

$lcp :==$latcp $lcp create port lta300: $lcp set port lta300:/service=able /node=router1 $set host/dte lta300:

VMS Version 5.5 or Later System

To connect to a VMS host running VMS Version 5.5 or later software, you must turn on the outgoing connections of the VMS LAT hosts and use the Digital set host/lat command, as shown in the following example:

$lcp :== $latcp $lcp set node/connection =outgoing $set host/lat able

Port Names When Configuring a LAT Printer

When you configure a LAT printer, the LAT port name is the line number without a “TTY” designation on the show lines command output. For example, if you configure terminal line 10 (named ABLE) to be a LAT printer port, you must use the OpenVMS command to associate an arbitrary LAT device to the LAT port name, as follows:

$lcp :== $lcp $lcp create port lta300: $lcp set port/node=ABLE/port=10 lta300:

The LAT port name is the line number without the “TTY,” regardless of whether the format of the TTY line number is decimal or octal.

Additional LAT Capability

The Cisco IOS software fully supports the LAT protocol suite, and provides the following features:

  • High-speed buffering—Handles a full screen of data (2000 characters) at full speed without requiring additional flow control.
  • Protocol transparency —Handles connections transparently. The user needs no protocol information to establish a connection.
  • Simplified configuration management—Uses logical names for LAT group codes to simplify the network structure.
  • Maintenance Operation Protocol (MOP)—Supports the Digital protocol to support the request ID message, periodic system ID messages, and the remote console carrier functions for Ethernet interfaces.

LAT Configuration Task List

The Cisco IOS software LAT protocol is supplied with a default configuration and does not require additional configuration for you to use it.

To enable LAT and customize LAT for your particular network environment, perform the tasks described in the following sections:

  • Configuring Basic LAT Services (Required for Service)
  • Enabling Inbound Services (As Required)
  • Controlling Service Announcements and Service Solicitation (As Required)
  • Configuring Traffic Timers (As Required)
  • Optimizing Performance (As Required)
  • Defining LAT Access Lists (As Required)
  • Enabling Remote LAT Modification (As Required)
  • Making LAT Connections (Required for Making Connections)

The section “Monitoring and Maintaining LAT Connections” later in this chapter provides tips for maintaining LAT connections. The section “LAT Configuration and Connection Examples” later in this chapter provides LAT configuration examples.

Configuring Basic LAT Services

To enable basic LAT services, use the following commands beginning in interface configuration mode:

Router(config-if)# lat enabled

Enables the LAT protocol. LAT is disabled by default.

Router(config-if)# lat node node-name

Gives the router a LAT node name that is different than the host name.

Router(config-line)# lat out-group <groupname number | range | all >

(Optional) Defines the group list for an outgoing connection on a specified line.

Router(config)# l at group-list groupname <number | range | all > [ enabled | disabled ]

(Optional) Specifies logical names for group lists.

Router(config)# lat service-group <groupname | number | range | all > [ enabled | disabled >

(Optional) Specifies groups to be advertised.

Router(config-line)# lat remote-modification

(Optional) Enables remote LAT modification of line characteristics.

Use the lat out-group command to define the list of services to which a user can connect. You create this list by defining the group code lists used for connections from specific lines. You can limit the connection choices for an individual line by defining the group code lists for an outgoing connection. When a user initiates a connection with a LAT host, the line of the user must share a common group number with the remote LAT host before a connection can be made.

Use the lat group-list command to specify a name for group lists to simplify the task of entering individual group codes. A name makes it easier to refer to a long list of group code numbers. To display the defined groups, use the show lat groups command.

Use the lat service-group command to specify a group code mask to use when advertising all services for a node. You can enter more than one group code by listing the numbers. You can also enter both a group code name and group codes.

Use the lat remote-modification line configuration command to configure a LAT line so that a remote LAT node can change the operating characteristics of the line.

Enabling Inbound Services

Just as LAT services are offered by host computers, they also can be offered by access servers and routers, because they implement both the host and server portions of the LAT protocol. This capability allows connections from either hosts or local access servers or routers. A host connected to a local device is called a host-initiated connection.

The tasks described in this section define support for host-initiated connections. This support includes refining the list of services that the router will support. An incoming session can be to either a port or a service. The port name is the terminal line number, as reported by the show users all EXEC command.

To enable inbound services, use the following commands in global configuration mode as needed:

Router(config)# lat service service-name password password

Sets the LAT password for a service.

Router(config)# lat service service-name ident identification

Sets the LAT service ID for a specific service.

Router(config)# lat service service-name rating static-rating

Specifies a static service rating for a specific service.

Router(config)# lat service service-name rotary group

Configures a LAT rotary group.

Router(config)# lat service service-name autocommand command

Associates a command with a specific service for auto-execution.

Router(config)# lat service service-name enabled

Enables inbound connections to a specific service.

Use the show lat advertised EXEC command to display LAT services offered to other systems on the network.

A service must be specifically enabled, but not all of the attributes in the previous task table are necessary in a particular environment.

Controlling Service Announcements and Service Solicitation

You can configure the Cisco IOS software to support the service responder feature that is part of the LAT Version 5.2 specification.

Specifically, the DECserver90L+, which has less memory than other Digital servers, does not maintain a cache of learned services. Instead, the DECserver90L+ solicits information about services as they are needed.

LAT Version 5.2 nodes can respond for themselves, but LAT Version 5.1 nodes, for example, VMS Version 5.4 or earlier nodes, cannot. Instead, a LAT Version 5.2 node configured as a service responder can respond in proxy for those LAT Version 5.1 nodes.

The Cisco IOS software can be configured as a LAT service responder. Of course, if all your nodes are LAT Version 5.2 nodes, you need not enable the service responder features.

To control service announcements and service solicitations, use the following commands in global configuration mode:

Router(config)# lat service-responder

Enables a proxy node to respond to solicit-information multicast messages.

Router(config)# no lat service-announcements

Disables periodic broadcasts of service advertisements.

Router(config)# lat service-timer interval

Adjusts the time between service announcements.

Use the lat service-responder command to configure the Cisco IOS software to respond to solicit information requests addressed to LAT Version 5.1 nodes. This function allows nodes that do not cache service advertisements to interoperate with nodes that do not respond to solicit requests. Figure 1 shows how a router can act as a proxy for LAT servers.

Figure 1 Router as Proxy for LAT Server

68874.jpg

The DECserver90L+ broadcasts a solicit information request in search of service for address Stella. The VMS host, Stella, is unable to respond to the request because it is running LAT Version 5.1. The access server is running LAT Version 5.2 with service responder enabled and informs the DECserver90L+ of the address for Stella.

Use the no lat service-announcements command to disable periodic broadcasts of service announcements. If service announcements are enabled, the LAT node will periodically broadcast service advertisements. If service announcements are disabled, the LAT node will not send service announcements, so a remote node requiring connection to the local node must use solicit-information messages to look up node information. Disable service announcements only if all of the nodes on the LAN support the service responder feature.

Use the lat service-timer command to adjust the time between LAT service advertisements for services offered. This command is useful in large networks with many LAT services and limited bandwidth.

Configuring Traffic Timers

You can customize the environment for sending LAT messages. The Cisco IOS implementation of LAT allows you to set the following features:

  • The number of retransmissions before declaring a system unreachable
  • The interval of time LAT waits before sending a keepalive message on an idle connection
  • The interval of time LAT waits between transmission of messages

These features affect all LAT connection types.

To enable these features, use the following commands in global configuration mode:

Router(config)# lat retransmit-limit number

Sets the message retransmit limit .

Router(config)# lat ka-timer seconds

Sets the keepalive timer .

Router(config)# lat vc-timer milliseconds

Sets the virtual circuit timer .

Optimizing Performance

To optimize performance for your LAT environment, use the following commands beginning in global configuration mode:

Router(config)# lat vc-sessions number

Sets the maximum number of sessions on a LAT virtual circuit. The maximum (and default) number of sessions is 255.

Router(config)# lat host-buffers receive-buffers

Allows a LAT host node to receive more than one message at a time.

Router(config)# lat server-buffers receive-buffers

Allows a LAT server node to receive more than one message at a time.

Router(config)# lat host-delay number

Specifies the delay acknowledgment for incoming LAT slave connections, where number is milliseconds.

Use the lat host-buffers command to set the number of messages received by a host at one time. Increasing this number can enhance performance. Before LAT Version 5.2, LAT allowed only one outstanding message at one time on a virtual circuit. This restriction could limit the performance of the Cisco IOS software when it processed a large number of messages because only one Ethernet packet of data could be in transit at a time. During virtual circuit startup, each side communicates to the other how many outstanding messages it is willing to accept.

Use the lat server-buffers command to set the number of messages received by a server at one time. Increasing this number can enhance performance. Before LAT Version 5.2, LAT allowed only one outstanding message at one time on a virtual circuit. This restriction could limit the performance of Cisco IOS software when it processed a large number of messages because only one Ethernet packet of data could be in transit at a time. With LAT Version 5.2, nodes can indicate that they are willing to receive more than one message at a time. During virtual circuit startup, each side communicates to the other how many outstanding messages it is willing to accept.

Use the lat host-delay command to set a user-defined delay for the acknowledgment for incoming LAT slave connections. This command is useful in situations where you need to control the delay. For example, if data is being transferred between a Digital server (using LAT) and a UNIX host (using Telnet) via a protocol translator, the protocol translator imposes the LAT delay on the Telnet and the LAT service, where Telnet may time out due to the LAT restriction.

Defining LAT Access Lists

Because LAT groups were not intended to implement security or access control, the Cisco IOS software supports access lists to provide these functions. An access list is a sequential collection of permit and deny conditions that serve to restrict access to or from LAT nodes on a specific terminal line. Each access list statement defines a permit or deny condition and a matching criterion for the node name.

When a LAT connection is attempted (either incoming or outgoing), the node name of the destination service (not the service name) is compared against the regular expression. If they match, the connection is permitted or denied as specified.

To define access lists and conditions, use the following commands beginning in global configuration mode:

Похожие статьи