1.2.2 Set 'transport input ssh' for 'line vty' connections

Information

Selects the Secure Shell (SSH) protocol.

Configuring VTY access control restricts remote access to only those authorized to manage the device and prevents unauthorized users from accessing the system.

Solution

Apply SSH to transport input on all VTY management lines

hostname(config)#line vty <line-number> <ending-line-number>
hostname(config-line)#transport input ssh

Impact:

To reduce risk of unauthorized access, organizations should require all VTY management line protocols to be limited to ssh.

See Also

https://workbench.cisecurity.org/benchmarks/12917

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), CSCv7|4.5

Plugin: Cisco

Control ID: cd6eb1e091f11beb280e3390629ce75c62f5346f3f2acaf166f0463d2227cba1