6500/4000交换引擎: set ip http server disable//关闭http服务 set ip permit enable snmp//限制SNMP源地址 set snmp comm. read-only//清空预设的SNMP COMM字 set snmp comm. read-write set snmp comm. read-write-all
8500、7500、MSFC等IOS设备: no ip http server//关闭http服务 no snmp//关闭snmp服务 no service dhcp//关闭 dhcp 服务 no ip finger//关闭 finger 服务 no service tcp-small-server//关闭tcp基本服务 no service udp-small-server//关闭 udp基本服务 service password-encryption//启用明文密码加密服务
设置中继设备: inter lo 0 ip address 10.10.1.100 255.255.255.255 ip telnet source-interface Loopback0 //发起telnet的源地址 设置受控设备: access-list 91 remark Hosts allowed to TELNET in access-list 91 permit 10.10.1.100 access-list 91 permit 10.10.1.101 line con 0 password xxxxxxxx line vty 0 4 password xxxxxxxx access-class 91 in