Access Control List trên CisCo CBS350

Cấu hình access list block địa chi ip tấn công 118.123.178.29 sau khi nghi nhận log gây mất kết nối ssh của mấy anh hàng xóm.

16-Apr-2025 10:17:18 :%SSHD-I-SSHSUCC: Connection ID 21 – SSH Session request from 118.123.178.29 port 57771 to Local address 10.11.88.1 port 22, username ‘taobao’ using crypto cipher aes128-gcm@openssh.com, hmac succeeded.

16-Apr-2025 10:16:41 :%SSHD-I-SHUTDWN: Connection ID 19 – from 118.123.178.29 port 46521 closed. Reason: idle connection timeout expired

16-Apr-2025 10:15:39 :%SSHD-I-SHUTDWN: Connection ID 19 – from 118.123.178.29 port 54749 closed. Reason: Connection closed

  1. show access-lists
    • Extended IP access list hack
    • deny ip host 118.123.178.29 any ace-priority 20
    • permit ip any any ace-priority 40
  2. interface vlan xx
    • ip address 172.16.xx.1 255.255.255.0
    • service-acl input hack

Leave a Reply