1.2.11 Set 'transport input none' for 'line aux 0'


When you want to allow only an outgoing connection on a line, use the no exec command.


Unused ports should be disabled, if not required, since they provide a potential access path for attackers. Some devices include both an auxiliary and console port that can be used to locally connect to and configure the device. The console port is normally the primary port used to configure the device; even when remote, backup administration is required via console server or Keyboard, Video, Mouse (KVM) hardware. The auxiliary port is primarily used for dial-up administration via an external modem; instead, use other available methods.


Organizations should prevent all unauthorized access of auxiliary ports by disabling all protocols using the 'transport input none' command.


Disable the inbound connections on the auxiliary port.

hostname(config)#line aux 0
hostname(config-line)#transport input none

See Also


Item Details


References: 800-53|AC-11, CSCv7|16.11

Plugin: Cisco

Control ID: fa0c5608b131ae32fd39d8e81b5f809de4821ba489d51275547f28f04a3f4e75