9-59
Cisco MGX 8850 (PXM1E/PXM45), Cisco MGX 8950, Cisco MGX 8830, and Cisco MGX 8880 Configuration Guide
Release 5.0.10, OL-3845-01 Rev. B0, August 16, 2004
Chapter 9 Switch Operating Procedures
Managing Telnet Access Features
If you are using SSH client software to access Cisco MGX switches, consider disabling Telnet client
access so that the switch accepts only secure sessions. To disable Telnet client access, enter the
cnfndparms command, select option number for Telnet Access To Node Disabled, and confirm the
action (Y) as shown in the following example:
PXM1E_SJ.7.PXM.a > cnfndparms
PXM1E_SJ System Rev: 04.09 May. 08, 2000 22:50:01 GMT
MGX8850 Node Alarm: NONE
NODE CONFIGURATION OPTIONS
Opt# Value Type Description
---- ----- ---- -----------
1 3600 16bit Decimal SHM Card Reset Sliding Window (secs)
2 3 8bit Decimal SHM Max Card Resets Per Window (0 = infinite)
3 Yes Boolean Core Redundancy Enabled
4 0x0 8bit Hex Required Power Supply Module Bitmap
5 0x0 8bit Hex Required Fan Tray Unit Bitmap
6 0 8bit Decimal Trap Manager Aging timeout value(Hour(s))
7 atm0 8bit Decimal Primary IP interface for Netmgmt
8 lnPci0 8bit Decimal Secondary IP interface for Netmgmt
9 Yes Boolean Auto Setting of Cellbus Clock Rate Enabled
10 Yes Boolean Inband Node-to-Node IP Connectivity Enabled
11 0 8bit Decimal 0 No Gang, 1 Left, 2 Right, 3 Both Present
12 0 8bit Decimal Card Switchover on Backcard FRU mismatch
13 No Boolean Card-to-Card High Priority LCN Disabled
14 No Boolean Telnet Access To Node Disabled
Enter option number (1-14): 14
NODE CONFIGURATION OPTIONS
Opt# Value Type Description
---- ----- ---- -----------
14 No Boolean Telnet Access To Node Disabled
Enable/Disable telnet access to this node. If option set to:
Yes: Telnet access to this node is disabled. This
forces all incoming telnet connections to be rejected by
the node's telnet server. Use of another protocol such as SSH
is needed to remotely log into a terminal session on the node.
No: Telnet access to this node is enabled. This is the default.
Incoming telnet connections will be accepted by the node's
telnet server. Use of other protocols such as SSH are still
supported for remotely logging into a terminal session on the
node.
Enter value for option 14 (Y/N): y
NODE CONFIGURATION OPTIONS
Opt# Value Type Description
---- ----- ---- -----------
14 Yes Boolean Telnet Access To Node Disabled
To test whether Telnet access is disabled, try to establish a session with the switch. In the following
example, a Telnet client attempts to connect to a switch on which Telnet access is disabled:
Err: access denied
<Your 'TELNET' connection has terminated>
Comments to this Manuals