1.2.2 Set 'transport input ssh' for 'line vty' connections

Information

Selects the Secure Shell (SSH) protocol.

Rationale:

Configuring VTY access control restricts remote access to only those authorized to manage the device and prevents unauthorized users from accessing the system.

Solution

Apply SSH to transport input on all VTY management lines

hostname(config)#line vty <line-number> <ending-line-number>
hostname(config-line)#transport input ssh

Impact:

To reduce risk of unauthorized access, organizations should require all VTY management line protocols to be limited to ssh.

References:

http://www.cisco.com/en/US/docs/ios/termserv/command/reference/tsv_s1.html#wp1069219

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CSCv6|3.4

Plugin: Cisco

Control ID: 9f26cfeebdeef73f2eb0ab6129260e5b4f238125f6af16e7a5813801aa36baf0