IntermediatePublished 2026-06-25
Secure Router VTY with ACL: Only Management Host Allowed
Bundle lab
Configure a standard IPv4 ACL and bind it to the VTY lines on the HQ router so only the dedicated management host can SSH to it. Confirm that regular routed traffic between sites is unaffected, and prove both a permitted and a denied management attempt.
Learning objectives
- Build a standard IPv4 ACL that permits a specific management host and denies others
- Apply the ACL correctly to VTY lines using the access-class command
- Maintain end-to-end routed data connectivity while restricting management-plane access
- Verify permitted and denied VTY access from different hosts
- Troubleshoot common ACL and access-class misconfigurations
Troubleshooting focus
- SSH is blocked from every source, MGMT-HOST included: Confirm the permitted host address is exactly 10.10.10.10 and that its permit sits above any broader denies.; Ensure SSH is fully configured: username with secret, ip domain name, RSA key,
ip ssh version 2, login local, and transport input ssh. ssh admin@10.0.23.1from USER-HOST still reaches a login prompt: Ensure the deny any is in place. The implicit deny exists, but a stray broader permit shadows it.- Pings between hosts fail after the change: You may have applied the ACL to a physical interface, or used an extended ACL incorrectly. Remove any interface access-group and keep the control on the VTY lines only.; Validate static routes in each direction; branch defaults point to HQ and HQ has specific routes back to both LANs.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.