# Cisco IOS Telnet Server and Client

**URL:** https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348
**Category:** Lessons Discussion
**Created:** [December 29, 2016, 9:27pm UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348 "2016-12-29T21:27:50Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 29, 2016, 9:27pm UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/1 "2016-12-29T21:27:50Z")

</div>

This topic is to discuss the following lesson:

> **[Cisco IOS Telnet Server and Client](https://networklessons.com/system-management/cisco-ios-telnet-server-client)**
>
> This lesson explains how to configure the Telnet server on your Cisco IOS router or switch and how to use the telnet client to connect to other ports.

---

<div class="post-metadata">

### Author: ![vallia](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/v/85e7bf/32.png) [@vallia](https://forum.networklessons.com/u/vallia)
#### Post date: [July 20, 2016, 12:20am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/2 "2016-07-20T00:20:56Z")

</div>

Please translate the following sentence:

“Telnet is niet secure dus liever niet gebruiken…”

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 26, 2016, 6:21pm UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/3 "2016-07-26T18:21:34Z")

</div>

Hi Valli,

Just removed this, this was a bit of my draft (in Dutch 🙂

Rene

---

<div class="post-metadata">

### Author: ![hroger](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/hroger/32/1552_2.png) [@hroger](https://forum.networklessons.com/u/hroger)
#### Post date: [May 21, 2019, 11:17am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/4 "2019-05-21T11:17:12Z")

</div>

I think it is better to create the credentials “user and password” before typing the command `login local`, because in case of problems (if you lose control), the equipment will ask you an account that you have not created yet.  
Am I wright ?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [May 21, 2019, 12:15pm UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/5 "2019-05-21T12:15:46Z")

</div>

Hello Hugues

Yes, if you type the command `login local` and log out without creating any credentials, then you will not be able to log back in.

Laz

---

<div class="post-metadata">

### Author: ![m1dagne](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/m/34f0e0/32.png) [@m1dagne](https://forum.networklessons.com/u/m1dagne)
#### Post date: [August 27, 2019, 5:21pm UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/6 "2019-08-27T17:21:57Z")

</div>

Hi Laz, first I would like to thankyou for your quick response. Just to be specific, I was working on CCNA routing & switching ICND1 100-105, Unit 7 Network Management, subtitle Telnet Server and Client. Here is what I found on packet tracer 7.1:

```
R2#telnet 192.168.12.1 ?
  <0-65535> Port number
  <cr>

```

as you see here I do not have the option to add a source address as explained on the lecture note after the command telnet 192.168.12.1 /source interface…

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [August 29, 2019, 6:22am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/7 "2019-08-29T06:22:25Z")

</div>

Hello Mintesinot

I tried it out myself and I confirm your findings. Unfortunately packet tracer does not include the whole list of available commands that exist on a real IOS device. This is one of those cases where it only includes a subset. However, keep in mind that for the specific exams (ICND1, ICND2, CCNA) the commands included in packet tracer are sufficient for your studies. The source interface command that Rene mentions in the lesson is useful to understand the concepts described, but it will not be necessary for the exams themselves.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![harshig89](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/h/3bc359/32.png) [@harshig89](https://forum.networklessons.com/u/harshig89)
#### Post date: [January 17, 2020, 6:31am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/8 "2020-01-17T06:31:22Z")

</div>

Difference between tacacs server, radius server and radius /tacacs client.  
I am trying to understand the basic difference between tacacs client and tacacs server and radius client and radius server and ISE .

Since TACACS+ is a cisco proprietary, we can only configure centralized server on CISCO ACS or CISCO ISE acting as TACACS server , while a windows 2012 server as centralized RADIUS server? while network access devices such as cisco switches, as either Tacacs clients or Radius clients with source interface vlan on switch that carries the radius or tacacs traffic towards the centralized servers ?

In shared authetnication model - your windows PC or macintosh laptop is a supplicant while your cisco switch is authenticator which authenticates using credentials of local directory on ise or LDAP on microsoft AD server ?

Is authentication done locally at cisco switch with response of Radius server from microsoft AD or tacacs+ CIsco ISE , or is it done all at end devices through secured tunnel ? I am not getting deeper in to authentication protocols like EAP FAST or PEAP. I just want to understand the device roles, as where the authentication process happens in between the three nodes starting with host supplicants, authenticator (network switch) and back end authentication device like ISE or microsft AD LDAP.

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [January 17, 2020, 6:51am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/9 "2020-01-17T06:51:55Z")

</div>

Hello Harshi

I just responded to this post here:

> [@AAA and 802.1X Authentication](https://forum.networklessons.com/t/aaa-and-802-1x-authentication/1153/27):
>
> Hello Harshi TACACS+ and RADIUS are two different families of protocols that perform similar functions. Some details about each: TACACS+ is Cisco proprietary but started out as an authentication for UNIX systems in the 1980s TACACS+ can be run on a VM, and there are versions that can be run on Windows as well TACACS+ uses TCP RADIUS is a protocol standardized by the IETF RADIUS can run on most Linux and Windows platforms RADIUS uses UDP by default but can also be configured to use TCP Both …

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![Vanilson\_pedro](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/v/4af34b/32.png) [@Vanilson\_pedro](https://forum.networklessons.com/u/Vanilson_pedro)
#### Post date: [September 3, 2020, 2:51pm UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/10 "2020-09-03T14:51:03Z")

</div>

Hi dear team!!

On this lesson you said this “If you use telnet, it’s best to use an access-list to restrict what devices are allowed to connect.”

Even though we do this.., an attacker can also try to change his IP to access the server… What else can we do to protect the telnet server and our network?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [September 5, 2020, 5:30am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/11 "2020-09-05T05:30:56Z")

</div>

Hello Vanilson

There are several things you can do to make your Telnet connection even more secure. Other than the access list, you can apply the following:

- Password protection and password policies - Use a password in the console and vty lines and set up your password policy so it only allows three failed attempts before blocking you out for a period of time.
- Use Management Plane Protection (MPP) (take a look [at the lesson for more info](https://networklessons.com/cisco/ccie-enterprise-infrastructuremanagement-plane-protection-mpphttps://networklessons.com/cisco/ccie-enterprise-infrastructuremanagement-plane-protection-mpp)) to restrict the interfaces via which the device permits packets from protocols such as Telnet.
- Use Control Plane Policing (CoPP) (see [lesson](https://networklessons.com/system-management/copp-control-plane-policing)) to ensure that the control plane of a device will not get so overwhelmed in a potential attack that Telnet traffic (and any management traffic) will not get processed correctly.

In addition to all of this, if you want to protect your communication session so that intercepted packets cannot be deciphered, it is preferable to use SSH as your management protocol.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![k19921130](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/k/9dc877/32.png) [@k19921130](https://forum.networklessons.com/u/k19921130)
#### Post date: [May 1, 2023, 4:28am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/12 "2023-05-01T04:28:55Z")

</div>

Hi Rene,  
If we will set vrf mgmt in Switch.  
How can I set ACL in line vty?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [May 4, 2023, 10:02am UTC](https://forum.networklessons.com/t/cisco-ios-telnet-server-and-client/1348/13 "2023-05-04T10:02:17Z")

</div>

Hello Eric

If you have VRFs configured on your device, then for you to access the VTY management interface from a particular VRF (other than the default one) you must apply the following command:

`Router(config-line)# access-class 1 in vrf-also`

By default incoming Telnet/SSH connections from interfaces that are part of a VRF instance are rejected. The `vrf-also` keyword must be applied so that incoming connections from interfaces on other VRFs will be accepted.

Starting from IOS XE 16.8.1 VRF awareness has been added to the access class line feature using the `vrfname` keyword. Specifically, you can do the following:

```auto
Device(config)# line vty 0 4
Device(config-line)# ipv6 access-class acl-name in vrfname vfrA

```

Note that you cannot use both VRF awareness and `vrf-also` on the same VTY line, as they are mutually exclusive commands.

More information about VRF awareness can be found at this Cisco documentation:

> **[Broadband Access Aggregation and DSL Configuration Guide, Cisco IOS XE...](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/bbdsl/configuration/xe-16-11/bba-xe-16-11-book/bba-xe-16-8-book_chapter_0100101.html#d71283e302a1635)**
>
> Broadband Access Aggregation and DSL Configuration Guide, Cisco IOS XE Gibraltar 16.11.x-VRF Awareness Access Class Line

I hope this has been helpful!

Laz
