Re: [c-nsp] Cisco disable ports 2001,4001,6001,9001
Marco Moock via cisco-nsp <[email protected]> Thu, 11 Dec 2025 15:21:13 +0100
| Newsgroups | gmane.network.nsp.cisco |
|---|---|
| Message-ID | <[email protected]> |
--===============2639766565264250547==
Content-Type: multipart/signed; boundary="Sig_/wW=dNq0o4Q2oROK6JM_fvxL";
protocol="application/pgp-signature"; micalg=pgp-sha512
Content-Transfer-Encoding: 7bit
--Sig_/wW=dNq0o4Q2oROK6JM_fvxL
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Am 11.12.2025 um 12:32:51 Uhr schrieb Nick Hilliard:
> Marco Moock via cisco-nsp wrote on 11/12/2025 11:48:
> > Certain Cisco models (in my case 800 series, e.g. C886vaw, 886w
> > etc.) have telnet services on port 2001,4001,6001 and 9001.
> >=20
> > What is the preferred way to disable them entirely (not firewalling
> > them), but keep telnet and ssh? =20
>=20
> This isn't telnet-to-the-device, it's remote access to physical
> ports. You can disable it easily using e.g. for serial console:
>=20
> line con 0
> transport preferred none
Thanks for the hint.
Which is the real console port here, is that con 0?
My device only has one that has the name console and AUX both on them.
cisco886va#sh line
Tty Typ Tx/Rx A Modem Roty AccO AccI Uses Noise Overruns =
Int
0 CTY - - - - 23 0 0 0/0 =
-
1 AUX 0/0 - - - - 23 0 0 0/0 =
-
* 10 VTY - - - - 23 6 0 0/0 =
-
* 11 VTY - - - - 23 2 0 0/0 =
-
12 VTY - - - - 23 0 0 0/0 =
-
13 VTY - - - - 23 0 0 0/0 =
-
14 VTY - - - - 23 0 0 0/0 =
-
Line(s) not in async mode -or- with no hardware support:=20
2-9
I want to allow local access via RS232, but disallow the "remote access
to physical ports".
I've now checked and line aux 0 is responsible for the open ports here.
transport input none disabled the remote access on port
2001,4001,6001,9001.
How does that affect the local console port for accessing the device
itself?
--=20
Gru=C3=9F
Marco
Send unsolicited bulk mail to [email protected]
--Sig_/wW=dNq0o4Q2oROK6JM_fvxL
Content-Type: application/pgp-signature
Content-Description: Digitale Signatur von OpenPGP
Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEpXefSZn9R6zNZtTQE76RLz2tRfAFAmk601kACgkQE76RLz2t
RfCMBxAAi7pwfgQSpmS61tcR4/UsjRyZAlVcCqm/KM4xyg2UkjHhiqjNJgmLVbSj
UNfztVd7u9Ur1rSbbxWDnnDNNMkOGel22yFruV3w6M4xE0SaI7JbUtaX3MuJG7MT
zF2BEx6YTJOWYnoFdnNQwomw7E8F9R+diMyqlsoRWExc/RT6C/pB9mJLUT7dmgGO
VROiKAAHJbw9gjbdtvpGgaZxkGmXV2aGBG84E4TXJ6+/QXAwdThoP0lxABnIRTJh
pwYPsbU4cDw3PZA16K8bNcWao92ZIQ2iXvWvEt7HLQmHTfMbU+/l77gfTJOQiMCE
G1rnxcv/yx1rDkECYqvha8qenGXoFEB9fGHH9UWdAuahzR87wpHfraiJFcXzYcT7
1phlAVL+njA7AeKz/HuiNNErbITnrxvSd5b5LkuWKbxf3qxWobTbp3tj8bSg8RTR
MuW2pz3mboXoCLqfNh3y6iQ4AMkHWnpCbAX9AW4GIxawTMUyauafApyesMGtEmit
F4i2yXnz2bUUtsf53rZI1X0kAzfzX9E3+BnTJ4P5+29JDZrrcklCzXzsHDVI6rCF
LpdhX0bIZWP1AulG50Z/Pl9ZgqCHBczqUVv0MjZIJugZVVVIVWINV/pQauQV0/jH
F12TYAB6wbwR1ymrWMoKWuISVJXQ3/mUYfIL8pGUgONjjcR+ElU=
=3D+n
-----END PGP SIGNATURE-----
--Sig_/wW=dNq0o4Q2oROK6JM_fvxL--
--===============2639766565264250547==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KY2lzY28tbnNw
IG1haWxpbmcgbGlzdCAgY2lzY28tbnNwQHB1Y2submV0aGVyLm5ldApodHRwczovL3B1Y2submV0
aGVyLm5ldC9tYWlsbWFuL2xpc3RpbmZvL2Npc2NvLW5zcAphcmNoaXZlIGF0IGh0dHA6Ly9wdWNr
Lm5ldGhlci5uZXQvcGlwZXJtYWlsL2Npc2NvLW5zcC8K
--===============2639766565264250547==--